CSIDB logo
Threat actor

DERP Trolling

Attribution profile

Type
Sensationalist
Location
Russia
Known incidents
7 incidents
First seen
2013-12-30
Last seen
2014-02-11
Updated
2026-08-01 08:32
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

DERP Trolling is a hacker group known by that alias and, according to available information, operates from Russia. The group has primarily targeted online gaming services such as Steam, Origin, Battle.net, League of Legends, World of Tanks and EA.com, as well as a Cloudflare client in a separate incident. Their observed activities consist of distributed denial‑of‑service attacks aimed at disrupting the availability of those platforms, indicating a strategic objective focused on service disruption rather than financial gain or espionage.

The group’s tactical approach relies on DDoS tooling rather than malware or intrusion techniques. They have employed a tool they refer to as the “Gaben Laser Beam,” which they also describe as an “Ion Cannon” DDoS utility, and they have leveraged Network Time Protocol reflection to amplify traffic, as demonstrated in a February 2014 attack that generated over 400 gigabits per second against a Cloudflare client. Initial access vectors are not described in the source material, and no specific malware families are associated with their operations. DERP Trolling has solicited target requests through a public phone number and Twitter posts, allowing others to suggest victims for their DDoS tool.

Notable campaigns include the massive NTP reflection DDoS in February 2014 that struck a Cloudflare client and the January 2014 series of attacks on multiple gaming platforms where they claimed responsibility for disruptions to Origin, Battle.net, League of Legends, World of Tanks and EA.com using the Gaben Laser Beam tool. While the group denied direct involvement in the personal harassment and swatting of a prominent game streamer, their DDoS actions occurred amid that broader online vendetta, and they provided a channel for the public to request additional targets. No public attribution to a state sponsor or criminal consortium has been established in the referenced reports.

Incidents

Attributed incidents are available to members.

7 incidents
CSIDB