Tor network flooded with new relays by Lizard Squad, group allegedly behind Xbox Live and PSN attacks
Hackers allegedly behind Xbox and PlayStation network shutdown set sights on Tor — The group that allegedly took down Microsoft and Sony's gaming networks now says it's set its sights on a new target.
Context & Ripple Effects
The flood of new Tor relays caps a rapid escalation by Lizard Squad. Days earlier, the group's Christmas-time takedowns of Xbox Live and PlayStation Network made it famous — The Daily Dot's profile of the group traced how the attacks worked and who was involved — and by December 31 it had converted that notoriety into a product: a paid DDoS-for-hire service priced at $6 to $500 per attack, with the gaming-network shutdowns openly described as a marketing scheme.
First-order effects
- Tor users face degraded anonymity immediately: an attacker controlling a large share of newly added relays is positioned to observe or manipulate traffic passing through the network, forcing the Tor project to identify and filter malicious nodes.
Second-order effects
- The Tor operation feeds the group's commercial engine — Lizard Stresser, which Krebs on Security later found runs mostly on thousands of hacked home routers — showing the same botnet infrastructure serving both high-profile stunts and the paid attack service.
Third-order effects
- Law-enforcement pressure follows the publicity: within days of the Tor flood, U.K. police arrested an alleged Lizard Squad hacker, suggesting that visibility gained through attacks on consumer services shortens the runway for the operators behind them — though attribution in this case remains alleged throughout the coverage.
The trend: Attention-hungry hacking groups are turning disruptive attacks into marketing funnels for commercial DDoS services, with volunteer-run trust infrastructure like Tor becoming collateral targets.