Has The WikiBoat been sunk?

Updated happygeek 1 Tallied Votes 284 Views Share

The FBI took claims by new hacking group The WikiBoat that it was going to bring down the likes of Apple and Tesco last Friday at 4pm so seriously that it sent email warnings to those targeted. It's now Sunday morning, and the threatened DDoS attacks do not appear to have happened. So has The WikiBoat been sunk and is #OpNewSon a failure?
dweb-wikiboat
The answers would appear to be that it was never actually launched, but that doesn't mean that #OpNewSon is a failure or that this is the last we will hear from The WikiBoat in my opinion.

Let's look at the declaration from The WikiBoat which started the whole thing off:

"We, #TheWikiBoat would like to introduce this press release on our very first operation: Operation NewSon (OpNewSon). As previously stated, we have no motives other then doing it all for the lulz. However this operation will be slightly different and will somewhat change our already stated objective on doing it for the lulz. On the day of the operation, we plan to hit and attack several high corporate entities. Shortly after the start of the operation, we plan to release precious classified data on the already set out list of targets we do have. Those targets are none other then the ones who ultimately rule: the high revenue making companies of the world. While attacking the major companies of this planet may seem lulzy, we also wish that this operation make a difference. We are "sticking it to the man" so to speak. Our hopes are set out on this being a major operation because after all, we will be hitting major corporate/incorporate associations.

This operation has three parts to it.

1 - Spread the word of OpNewSon

This part is already in effect. We just need everyone to spread the word that a major operation is coming up real soon. The goal is for this message to get at least 5,000 views. Please spread the word of this operation in any way you can. Twitter, Facebook, YouTube, etc. Let the corporate entities know that we are coming.

2 - The online protests

This is where we need your help! Online protesting is simple and effective. All that's needed is enough people with the power to stand up to those who ultimately rule the world. We ask that you join us on the day of the 25th (May) in our IRC for further
instructions on our planned protesting.

[instructions deleted by DaniWeb]

Until then, here's how you can ready up...We're going to be DDoS'ing the targets. DDoS takes a website offline for a certain amount of time depending on how many people are participating in the attack. These easy meaningful attacks are actually quite effective and have huge impacts. The tool we will be using is called LOIC.

Download here: [URL deleted by DaniWeb]

We'll explain how to use LOIC as well as which targets we'll be hitting on the 25th of May. More information and updates will also become available on

Twitter: @AnonymousWiki @AnonymouSpoon @MehIzDanneh @TibitXimer @Anonymau

3 - The attacks

This phase will be the most powerful. By the time this phase is initiated, all targets will have been downed (DDoS'd) for at least 2 hours. This phase is all about leaking highly classified data from the targets.

THIS OPERATION WILL COMMENCE ON MAY 25th, 2012

Spread the word as much as possible as we plan to take on the great elite."

From this we can determine that TheWikiBoat has certainly succeeded with phase one, spreading the word about #OpNewSon and making a name for itself in the process. The online coverage in advance of the proposed attacks was plentiful, and the FBI seemed to take it very seriously indeed which gives the group added kudos. Phase two is a little more difficult to determine whether successful or not, chatter across an IRC channel is not a hugely anarchic tactic after all. That said, phase three does appear to have been a FAIL, assuming you believe that it was ever intended to be taken seriously in the first place.

I have grave doubts that it was. In fact I would go so far as to say that phase three and phase one were one and the same thing: generate as much publicity about TheWikiBoat as possible. After all, who announces details of sites that are going to be hit with a DDoS attack ahead of actually hitting them? It makes no sense at all, other than to perhaps create a sense of fear amongst those being named. All it would really accomplish is to ensure those sites, especially given the size of the ones so named, would get prepared and ensure that their defences were well and truly in place. No, I am convinced it was a publicity stunt, and as far as that goes it was far from a failure. The fact that the FBI took the step of sending out emails to warn large corporates of the risk is proof of that.

The inevitable associating of TheWikiBoat with Anonymous was probably all it took to get the attention of the FBI. Next time, I imagine that if any announcements are made they will be diversionary in nature and the real targets will be taken down without prior warning. I doubt very much that this is the last we will hear from TheWikiBoat...

Dani AI

Generated

A short, sourced recap and practical takeaway (context for later readers):

The group that branded itself TheWikiBoat publicly announced Operation NewSon in April 2012 and set a late‑May date for coordinated DDoS and data leaks; that publicism prompted an FBI/PPAU alert to InfraGard members and media coverage ahead of the date. (securityweek.com)

  • Security reporting and contemporaneous analysis trace the announcement to a Pastebin post and show the FBI warning was intended as a heads‑up for organizations to monitor and prepare. (sect.iij.ad.jp)

What actually happened: the May 25/26 mass operation largely failed to produce the promised outages on the scheduled date (IRC coordination collapsed and the channel was closed), though TheWikiBoat later resurfaced with smaller hits and some data leaks in June. That pattern — loud advance notice, limited initial impact, then sporadic follow‑up — is documented in incident writeups from the time. (sect.iij.ad.jp)

Interpretation tied to the thread: ’s read (publicity/recruitment motive) lines up with contemporaneous reporting; pre‑announcing large DDoS ops often serves to recruit and to intimidate rather than guarantee success. Tools pushed in those calls (e.g., LOIC) are low‑barrier but traceable and usually yield small-scale, volunteer‑driven traffic rather than botnet‑scale floods. (theregister.com)

Practical defensive checklist (actionable, time‑tested):

  • Treat any public threat as credible until proven otherwise; activate the IR playbook (prepare, detect, contain, recover). (csrc.nist.rip)
  • Contact ISP and any contracted DDoS/scrubbing provider early; enable CDN/WAF and rate‑limits where feasible. (cisa.gov)
  • Preserve synchronized logs and full packet captures for forensics; document timelines and communications. (csrc.nist.rip)
  • Coordinate with sector CERT / sharing networks (InfraGard, CERTs, or CISA where applicable) and law enforcement if required. (securityweek.com)

References: SecurityWeek (FBI/OpNewSon coverage), The Register (operation/LOIC analysis), IIJ security diary (day‑of timeline), DataBreaches/TheHackerNews (follow‑up activity), NIST SP 800‑61 and CISA DDoS guidance for IR and mitigation. (securityweek.com)

maria.methews 0 Newbie Poster

i don't thinks so ... its still floating i guess....

maramizo 0 Newbie Poster

Why did you even reply to this, it's ages old and obviously failed.

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

It's called 'signature spam' where someone posts to anything just in order to expose the advertising links in their sig - we see it all the time...

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.