The U.S. Department of Homeland Security's National Cybersecurity and Communications Integration Center (NCCIC) has issued a bulletin warning that the hacktivist collective Anonymous is developing and deploying at least four new cyber attack tools — a significant escalation from the group's historically crude capabilities.
Beyond LOIC: A New Arsenal
Anonymous has long relied on the Low Orbit Ion Cannon (LOIC), a rudimentary DDoS tool that enabled mass participation but left attackers easily traceable through IP address logs. Multiple arrests of Anonymous members were attributed to LOIC's lack of anonymization, prompting the collective to develop more sophisticated alternatives.
The NCCIC identified four new tools circulating among Anonymous members:
- #RefRef — A tool exploiting SQL vulnerabilities to launch denial-of-service attacks by forcing target servers to exhaust their own processing resources through benchmark function abuse
- Apache Killer — A DoS tool exploiting a memory exhaustion bug in Apache web servers (affecting all 1.3 and 2.0 versions), described by researchers as trivial to exploit and capable of crashing servers
- Anonware — A framework enabling inexperienced malware writers to infect executable files using .NET runtime compilation
- URGE (Universal Rapid Gamma Emitter) — A tool for hijacking Twitter trending topics to amplify Anonymous messaging campaigns
Tactics and Tradecraft
The bulletin notes that Anonymous routinely uses social media platforms to announce intended targets, ongoing attack results, and post stolen files — providing defenders an opportunity for proactive monitoring. The NCCIC observed significant reconnaissance activity preceding attacks, and warned that public announcements could serve as deliberate misdirection to distract from actual operations.
The NCCIC assessed "with high confidence that Anonymous and associated groups will continue to use existing and newly created tools to exploit vulnerable web servers, websites, computer networks and other digital information mediums."
Escalating Physical and Cyber Convergence
The bulletin highlighted Anonymous's increasing coordination of physical protests with cyber attacks, including the Bay Area Rapid Transit (BART) disruption in August 2011 and planned participation in the "Day of Rage" and Occupy Wall Street demonstrations. Announced targets included Barclays, Vodafone, Lockheed Martin, and Facebook.
While the NCCIC noted Anonymous had not yet demonstrated capability to damage critical infrastructure, it warned that the closely associated LulzSec group had shown moderately higher skill levels — and that the possibility of a higher-level actor providing advanced capabilities could not be ruled out.