Bad bots on the rise, targeting APIs

Share post:

Bad bots are getting cleverer, and as a result, more advanced attacks, such as account takeover and attacks against APIs, are increasing.

In June 2022, hackers launched an attack against Australia’s largest Chinese-language platform, Media Today, making over 20 million attempts to reset user passwords. The attackers weren’t humans, but bots—complex, automated programs that swarm around the internet carrying out instructions.

Bots can be benign or malicious. Benign bots, such as search engine crawlers, are used to harvest data for search engines. Malicious bots, on the other hand, are used to target digital systems, web applications, and application programming interfaces (APIs) for data theft, fraud, denial of service, and more.

Bad bots are evolving to become more sophisticated and are getting better at mimicking human behavior and bypassing traditional security controls. According to Imperva, bad bots accounted for just under half (48%) of all internet traffic in the first six months of 2023, up from 43% in the same period last year.

APIs are a growing target for bot attacks because they are relatively under-protected and used extensively for automated processes and communications. Attackers target applications that use APIs to access email accounts, such as marketing mailshot applications that send and track bulk- or personalized- emails to potential or existing customers.

The sources for this piece include an article in SecurityBrief.

SUBSCRIBE NOW

Related articles

AT&T Fined $13 Million for Supply Chain Data Breach

AT&T has agreed to pay a $13 million fine following a significant data breach that exposed information of...

Supply Chain Attack Weaponizes Communication Devices in Lebanon

A sophisticated supply chain attack has turned everyday communication devices into weapons in Lebanon, marking a new era...

Chinese Botnet “Raptor Train” Infects 260,000 Devices Worldwide

A massive Chinese botnet dubbed "Raptor Train" has been disrupted by the FBI and cybersecurity researchers. This sophisticated...

Multi-year spear-phishing campaign finally caught

U.S. federal prosecutors have indicted Wu Song, a Chinese national employed by state-owned Aviation Industry Corporation of China,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways