Steam suffers outage

Battlefail 6 okes, Chinese hackers getting bored Jan.

The Aisuru botnet attack that took place in 2024 was launched by individuals that were codenamed, "Snow", "Tom", and "Forky". Though they were assumed to be Chinese due to how the attack took place it wasn't conclusive. Several Asian, Russian, and South American ISPs were exploited. To date, no one has been caught.

This latest attack, that didn't only target Steam, is alleged to be another Aisuru botnet attack. This time around, it also involved several European IPs.

Big noise is being made about Steam's downtime. The question is, who was the actual target? It is not only gaming-related nodes that was attacked. It is also strange not seeing a big cybersecurity company putting out a preliminary report.

I use services, hosted on AWS, that had to undergo threat mitigation. They deemed the attack a severe risk, but all is restored now.

What I want to know is why it is being assumed that it is the Aisuru botnet? Now, there is a new Aisuru variant called Airashi, and all this was investigated, and researched, by QiAnXin Xlab who have a detailed blog. The last time the attack happened, the spread resolved to 144 IP addresses spanning 19 regions.

For those interested:


It is possible that cnPilot routers are still vulnerable. Anyhow, the attack could have originated anywhere. Just because there is a common pattern doesn't mean that it is the same attackers using the same botnet.

The Discord incident... I can see these attacks being lucrative.
 
A simple explainer:


AIRASHI Botnet​

Executive Summary

AIRASHI is a variant of the AISURU botnet that has been active since at least late 2024. It is in active development and has the capability to conduct large-scale DDoS attacks.​

Key Takeaways

  • AIRASHI is a variant of the AISURU botnet that has been active since at least late 2024.
  • AIRASHI uses a 0day vulnerability affecting cnPilot routers to spread itself.
  • AIRASHI’s infrastructure uses at least 60 different IP addresses, hosted in multiple countries, which may make it more difficult to dismantle the botnet.
  • Since AIRASHI is still under active development and has the capability to conduct large-scale DDoS attacks, PolySwarm analysts consider AIRASHI to be an emerging and evolving threat.
What is AIRASHI?

AIRASHI is a variant of the AISURU botnet that has been active since at least late 2024. QiAnXin XLab reported on AIRASHI.

AISURU botnet is known for a large-scale DDoS attack that occurred in August 2024. The attack targeted distribution platforms of the Chinese game Black Myth: Wukong. Targets included Steam and Perfect World. The attack occurred in four waves, aligning with peak gaming hours, to be as disruptive as possible. Following this attack, AISURU ceased activity in September 2024. An updated and streamlined version, dubbed kitty, was released in October 2024. In late 2024, the threat actors behind AISURU released the current version of AIRASHI, a new AISURU variant.

AIRASHI uses a 0day vulnerability affecting cnPilot routers to spread itself. It also spreads via Nday vulnerabilities and weak Telnet passwords. Sample strings use RC4 encryption, and the C2 communication uses HMAC-SHA256 for verification and ChaCha20 for encryption. The names used for C2 domains (including xlabresearch, xlabsecurity, and foxthreatnointel) appear to be an attempt to mock security researchers. AIRASHI’s infrastructure uses at least 60 different IP addresses, hosted in multiple countries, which may make it more difficult to dismantle the botnet.

AIRASHI is capable of stable T-level DDoS attacks, with a tested attack capacity of 1-3 Tbps. AIRASHI, which has been observed spreading to hundreds of machines per day, does not appear to target a particular vertical. However, a large number of targets have been located in China, Poland, Russia, and the US. AIRASHI is updated often and appears to be under active development. Like AISURU, it has the capability to conduct large-scale DDoS attacks. For these reasons, PolySwarm analysts consider AIRASHI to be an emerging and evolving threat.
 
The Aisuru botnet attack that took place in 2024 was launched by individuals that were codenamed, "Snow", "Tom", and "Forky". Though they were assumed to be Chinese due to how the attack took place it wasn't conclusive. Several Asian, Russian, and South American ISPs were exploited. To date, no one has been caught.

This latest attack, that didn't only target Steam, is alleged to be another Aisuru botnet attack. This time around, it also involved several European IPs.

Big noise is being made about Steam's downtime. The question is, who was the actual target? It is not only gaming-related nodes that was attacked. It is also strange not seeing a big cybersecurity company putting out a preliminary report.

I use services, hosted on AWS, that had to undergo threat mitigation. They deemed the attack a severe risk, but all is restored now.

What I want to know is why it is being assumed that it is the Aisuru botnet? Now, there is a new Aisuru variant called Airashi, and all this was investigated, and researched, by QiAnXin Xlab who have a detailed blog. The last time the attack happened, the spread resolved to 144 IP addresses spanning 19 regions.

For those interested:


It is possible that cnPilot routers are still vulnerable. Anyhow, the attack could have originated anywhere. Just because there is a common pattern doesn't mean that it is the same attackers using the same botnet.

The Discord incident... I can see these attacks being lucrative.
I still see issues on the App and even the steam site. Looks like a slow recovery.
 
GOG had plenty issues in the past. Google will help you recall.

Every web based service will at some point or another experience issues without exception, and there has not been any exceptions.

DRM is also a moot point at this stage in the industry. Its unwinnable and unavoidable. Embrace the system and consume. Then consume some more and keep on consuming.
 
Never went down for me. Guess I was lucky, on the JHB node.
I was on JHB node and I went down when DDOS attack happened as I couldn't log back in till the services started to recover and even then it took 5 minutes just to log back in as services was still recovering phase at the time and the store page wasn't working for a while till it recovered.
 
I was on JHB node and I went down when DDOS attack happened as I couldn't log back in till the services started to recover and even then it took 5 minutes just to log back in as services was still recovering phase at the time and the store page wasn't working for a while till it recovered.
Was still logged in and could browse the store on both my phone & PC. So no idea.
 
I only saw some issues with the page coding and app usage but very vaguely felt anything.

GOG uses cloudflare against DDoS attacks, they have had downtime before in the past but nothing substantial either. Steam is the more popular platform with the most users so it’s an obvious target.

I’m sure it won’t be the last.
 
Happens every few months like clockwork. Steam servers must be allergic to Tuesdays.
 
Top
Sign up to the MyBroadband newsletter
X