Hacktivists Target Israeli Rocket Alert Systems During Ongoing Conflict
Cloudflare reports immediate DDoS attacks and malicious app campaigns aimed at disrupting Israeli civilian rocket alert systems following the October 7 Hamas attack.
Cloudflare systems automatically detect and mitigate DDoS attacks against Israeli websites exactly twelve minutes after the initial Hamas attack on October 7. The first wave peaks at 100,000 requests per second and lasts ten minutes, followed by a larger second wave that hits one million requests per second. Smaller DDoS attacks continue to bombard these critical alert websites in the hours that follow.
Beyond network floods, pro-Palestinian hacktivist groups like AnonGhost actively exploit vulnerabilities in mobile applications that warn civilians of incoming rockets. These threat actors intercept requests, expose backend servers, and send terrifying fake alerts to users, including false warnings about incoming nuclear bombs. Additionally, hackers deface at least one Israeli website with anti-Semitic messages.
The Cloudforce One Threat Operations team also identifies malicious Android applications that impersonate the legitimate RedAlert rocket warning app. These fake apps trick users into granting access to highly sensitive data, including contact lists, SMS messages, call logs, and detailed device information. Cloudflare actively reaches out to affected organizations to offer protective support amidst this continued cyber bombardment.