BGP Hijack of Amazon DNS to Steal Crypto Currency
Yesterday morning we posted a tweet (below) that Amazon’s authoritative DNS service had been impacted by a routing (BGP) hijack. Little did we know this was part of an elaborate scheme to use the inherent security weaknesses of DNS and BGP to pilfer crypto currency, but that remarkable scenario appears to have taken place.
BGP hijack this morning affected Amazon DNS. eNet (AS10297) of Columbus, OH announced the following more-specifics of Amazon routes from 11:05 to 13:03 UTC today:
205.251.192.0/24
205.251.193.0/24
205.251.195.0/24
205.251.197.0/24
205.251.199.0/24— InternetIntelligence (@InternetIntel) April 24, 2018
After posting the hijack tweet, I observed reports of a DNS hijack relating to the cryptocurrency website myetherwallet.com and thought the two things might be related:
Maybe related to this: https://t.co/6dOrmEuRAz
— Doug Madory (@DougMadory) April 24, 2018
Sure enough, it appears that eNet/XLHost (AS10297) suffered a breach enabling attackers to impersonate Amazon’s authoritative DNS service. These attackers used AS10297 to announce five routes used by Amazon’s DNS:
205.251.192.0/24 Amazon.com, Inc.
205.251.193.0/24 Amazon.com, Inc.
205.251.195.0/24 Amazon.com, Inc.
205. Continue reading

The software integrates with public cloud APIs so that backups scale automatically as cloud workloads are added or deleted.
HPE says that Huawei's claim that is is partnering with HPE is not true. This is just the latest public relations problem for Huawei in the U.S.



