/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Lizard Squad's DDoS attack service “Lizard Stresser” runs mostly on thousands of hacked home routers

Brian Krebs / Krebs on Security :

Krebs on Security Brian Krebs

Context & Ripple Effects

Lizard Squad spent late December 2014 knocking Xbox Live and PlayStation Network offline — coverage traced the group behind the attacks that crippled both networks — then monetized the notoriety by launching Lizard Stresser, a DDoS-for-hire service priced from $6 to $500 that the group openly called a marketing scheme for its earlier outages.

Brian Krebs' new reporting supplies the missing infrastructure story: the booter's firepower comes mostly from thousands of hijacked home routers, meaning paying customers are renting botnets built from ordinary consumers' hardware rather than any dedicated attack platform.

First-order effects

  • Home router owners are the immediate victims: their devices are conscripted into Lizard Stresser's attack fleet without their knowledge, while buyers get cheap denial-of-service capacity sourced from consumer gear.
  • The finding undercuts Lizard Squad's framing of the service as a legitimate stress-testing tool — Krebs' exposure ties the product directly to criminal use of stolen bandwidth.

Second-order effects

  • Operating a customer-listed booter carries its own risk: within weeks, LizardStresser itself was hacked and its customer details made public, turning the buyer base into exposed targets.
  • Krebs' identification of the hacked-router supply chain gives ISPs and security researchers a concrete detection target, pressuring the service's capacity base at its source.

Third-order effects

  • The pattern — celebrity hacker groups converting outage stunts into subscription attack services running on unsecured consumer routers — foreshadows the commercial booter market that law enforcement later dismantled, as when WebStresser was shut down in 2018 after linking to millions of attacks.
  • If home routers remain the default raw material for DDoS-for-hire, responsibility for mitigation shifts toward device makers and ISPs to secure consumer hardware by default.

The trend: DDoS-for-hire is industrializing around compromised consumer routers, turning unsecured home networking hardware into rentable attack infrastructure.