{"id":5107,"date":"2026-10-07T08:23:24","date_gmt":"2026-10-07T08:23:24","guid":{"rendered":"https:\/\/cyberasia.io\/?p=5107"},"modified":"2026-10-07T08:23:32","modified_gmt":"2026-10-07T08:23:32","slug":"server-killers-us-government-sites-down","status":"publish","type":"post","link":"https:\/\/cyberasia.io\/article\/ddos\/server-killers-us-government-sites-down\/","title":{"rendered":"Server Killers: Revealed, 3 U.S. Government Sites Down"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Server Killers announced attacks on three United States government sites<\/mark><\/strong> on Thursday (17 September 2026), and check-host reports show that all three sites failed to open from nearly all of the visible monitoring nodes. The named sites are Science.gov, OSTI.gov, which belongs to the Department of Energy (DOE), and EFTPS.gov, the federal tax payment system under the Department of the Treasury.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The numbers are clear-cut. Of the 117 check results fully visible across the three reports, only one answered with a 200 (OK) code: the Vancouver, Canada node for EFTPS, with a response time of 6.49 seconds. All the rest recorded Connection timed out, including two nodes in Jakarta.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/Server-Killers-1024x576.jpg\" alt=\"Figure 1 : Server Killers logo with a hooded silhouette, a binary-code shield, and the Russian flag\" class=\"wp-image-5110\"\/ loading=\"eager\" fetchpriority=\"high\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/Server-Killers-1024x576.jpg 1024w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/Server-Killers-300x169.jpg 300w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/Server-Killers-768x432.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/Server-Killers.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Figure 1 : Server Killers logo with a hooded silhouette, a binary-code shield, and the Russian flag<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Sequence of Disruptions from EFTPS to OSTI<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">EFTPS was checked first. The check-host report for www.eftps.gov\/eftps\/ was recorded on Thursday 17 September 2026 at 14:10 UTC, equivalent to 21:10 WIB (Western Indonesia Time). This free Department of the Treasury service is used to pay federal taxes online, from income tax and employment tax to excise tax.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a browser, the EFTPS page displays <strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-red-color\">ERR_CONNECTION_CLOSED<\/mark><\/strong>, meaning the connection was abruptly closed from the server side. Check-host recorded Connection timed out at 40 of the 41 fully visible nodes, from Vienna, S\u00e3o Paulo, and Tokyo to Singapore and Stockholm. Only Vancouver got through.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140440_904-819x1024.jpg\" alt=\"Figure 2 : Server Killers and the EFTPS.gov disruption, check-host records only Vancouver responding with 200 (OK)\" class=\"wp-image-5111\"\/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140440_904-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140440_904-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140440_904-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140440_904.jpg 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><figcaption class=\"wp-element-caption\">Figure 2 : Server Killers and the EFTPS.gov disruption, check-host records only Vancouver responding with 200 (OK)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">About 44 minutes later, at 14:54 UTC (21:54 WIB), it was Science.gov&#8217;s turn. The Server Killers post for this site carries the note Duration: 1 hour and the hashtag<strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-purple-color\"> #ServerKillers<\/mark><\/strong>. All 39 monitoring nodes in the screenshot recorded Connection timed out.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140442_644-819x1024.jpg\" alt=\"Figure 3 : Server Killers and the Science.gov disruption, all check-host nodes record Connection timed out\" class=\"wp-image-5112\"\/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140442_644-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140442_644-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140442_644-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140442_644.jpg 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><figcaption class=\"wp-element-caption\">Figure 3 : Server Killers and the Science.gov disruption, all check-host nodes record Connection timed out<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The last report, for OSTI.gov, was recorded at 17:57 UTC, or 00:57 WIB on Friday 18 September. OSTI is the DOE office that collects, stores, and opens public access to scientific information from DOE-funded research. In its post, the group wrote &#8220;Full Infrastructure is strongly downed&#8221;, then linked a separate page whose title names some of the affected domains.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result was the same: of the 37 fully visible nodes, every one failed to connect within the time limit. The two targets are also related, because <strong><a href=\"https:\/\/science.osti.gov\/About\/STI\" data-type=\"link\" data-id=\"https:\/\/science.osti.gov\/About\/STI\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">the official DOE page lists Science.gov<\/mark><\/a><\/strong> as one of the resources managed by OSTI.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140445_198-819x1024.jpg\" alt=\"Figure 4 : Server Killers and the disruption of OSTI.gov, owned by the U.S. Department of Energy, on 17 September 2026\" class=\"wp-image-5113\"\/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140445_198-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140445_198-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140445_198-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/10\/IMG_20261007_140445_198.jpg 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><figcaption class=\"wp-element-caption\">Figure 4 : Server Killers and the disruption of OSTI.gov, owned by the U.S. Department of Energy, on 17 September 2026<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Who Is Server Killers and What Is Its Attack Pattern<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Server Killers logo combines a hooded silhouette, an orange shield over a binary-code background, Saint Basil&#8217;s Cathedral, and the Russian flag. Target descriptions are written in English, and some posts come with a Russian translation. The group&#8217;s location and number of members cannot be confirmed from the available evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threat intelligence firm <strong><a href=\"https:\/\/www.cyjax.com\/resources\/blog\/serverkillers-conducts-pro-russian-hacktivist-campaign-against-norway\" data-type=\"link\" data-id=\"https:\/\/www.cyjax.com\/resources\/blog\/serverkillers-conducts-pro-russian-hacktivist-campaign-against-norway\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Cyjax<\/mark><\/a><\/strong> notes that Server Killers has been active since at least early August 2023, focuses on DDoS attacks, and frequently targets Ukraine and the countries that support it. Its latest campaign targets Norway: as of 8 September 2026, 36 targets had been announced, accompanied by check-host links, some stating durations of between one and five hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/www.zerofox.com\/intelligence\/flash-report-ddos-attacks-target-spanish-government-websites\/\" data-type=\"link\" data-id=\"https:\/\/www.zerofox.com\/intelligence\/flash-report-ddos-attacks-target-spanish-government-websites\/\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">ZeroFox<\/mark><\/a><\/strong> adds that the group announced attacks on the United Kingdom, Poland, and Denmark, then on Spanish government sites in February 2026. The Server Killers posts about these three U.S. sites do not state any motive or demand.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Server Killers channel has a small reach. According to Cyjax, its new channel had only 112 subscribers in early September 2026, consistent with the 56, 44, and 58 views on the three posts we reviewed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For context on similar DDoS attacks, also read <a href=\"https:\/\/cyberasia.io\/articles\/\" data-type=\"link\" data-id=\"https:\/\/cyberasia.io\/articles\/\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">https:\/\/cyberasia.io\/articles\/<\/mark><\/strong><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Read Check-Host Results<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Check-host tests a single address from many locations at once. Connection timed out means the server did not respond within the time limit, while OK with a 200 code means the page opened normally. This report is a snapshot of a single moment, not a record of how long the disruption lasted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some things are not visible. The screenshots do not include <strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-red-color\">HTTP codes such as 502, 504, or 429<\/mark><\/strong>, so the attack vector cannot yet be determined: an HTTP request flood at layer 7 and a packet flood at the network layer can both produce this pattern. The only duration information, one hour for <strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-green-cyan-color\">Science.gov<\/mark><\/strong>, comes from Server Killers itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The list of monitoring nodes is also cut off in the middle of the alphabet, so results from locations in the United States do not appear. That matters, because the main users of all three sites are there. Simultaneous failures from Europe, Brazil, Japan, and Indonesia signal a widespread problem, but filtering of international traffic by the site operators cannot yet be ruled out as an explanation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Impact on Public Services and Tax Payments<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The evidence posted by Server Killers shows only an availability disruption, not a breach. The material reviewed contains no data samples, credential lists, or signs of access to internal systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">EFTPS is the most sensitive because it involves tax obligations. The <strong><a href=\"https:\/\/fiscal.treasury.gov\/payments-to-government\/electronic-federal-tax-payment-system-eftps\" data-type=\"link\" data-id=\"https:\/\/fiscal.treasury.gov\/payments-to-government\/electronic-federal-tax-payment-system-eftps\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Bureau of the Fiscal Service<\/mark><\/a><\/strong> under the Department of the Treasury states that taxpayers can pay through the eftps.gov site, by phone, or through intermediaries such as tax professionals, payroll services, and financial institutions. The phone and intermediary routes serve as backups when the online site is hard to open.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The case is different for Science.gov and OSTI.gov. Both are research access portals, so what is disrupted is access to scientific literature for researchers, students, and the public, not the operation of vital services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For readers in Indonesia, two Jakarta monitoring nodes recorded the same failure in all three reports, so access from inside the country was likely disrupted as well at the time of each check.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As of this writing, we found no official statement from any of the three agencies. Three things are worth monitoring: statements from the Department of the Treasury and DOE, when services recover, and whether Server Killers adds more U.S. targets after its wave against Norway.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Emergency Steps for Admins Under DDoS Attack<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The joint guidance from <strong><a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/understanding-and-responding-distributed-denial-service-attacks\" data-type=\"link\" data-id=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/understanding-and-responding-distributed-denial-service-attacks\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">CISA, FBI, and MS-ISAC<\/mark><\/a><\/strong> urges organizations to understand the DDoS protection their internet and cloud providers already have before an attack arrives. For admins already hit by a traffic surge like this, the following order of work makes sense:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Contact the ISP, hosting provider, or CDN to request upstream traffic filtering.<\/li>\n\n\n\n<li>Apply rate limiting and WAF rules to the heaviest paths, such as search, login, and payment.<\/li>\n\n\n\n<li>Serve static pages from cache or CDN, and temporarily turn off non-essential features.<\/li>\n\n\n\n<li>Keep access and firewall logs: source addresses, user-agents, and the URL paths being flooded.<\/li>\n\n\n\n<li>Separate critical services, such as authentication and payment, from the information site so that an attack on one part does not take everything down.<\/li>\n\n\n\n<li>Put up a status page and prepare alternative channels for users.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Q1 : Did the Server Killers attack leak tax data or personal data of U.S. citizens?<\/mark><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The available evidence does not show a leak. All that is visible is sites that cannot be opened, not copies of a database or access to internal panels. This pattern is common in DDoS attacks, which target the availability of a service, not the contents of its storage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Q2 : Did tax payments through EFTPS stop as well?<\/mark><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That cannot be confirmed yet. The 14:10 UTC timestamp only shows that the site could not be opened from nearly all nodes at that moment, not how long the disruption lasted or the condition of the payment system behind it. Taxpayers should use other official channels and monitor announcements from the operator.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Q3 : How can you tell a DDoS attack from an ordinary server outage?<\/mark><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Look at the pattern. Simultaneous timeouts in many locations, a surge of requests from many IP addresses, or a single URL path being flooded point to DDoS. An ordinary outage is more often accompanied by consistent 5xx codes and traces of configuration or hardware changes in the logs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Server Killers announced attacks on three United States government sites on Thursday (17 September 2026), and check-host reports show that all three sites failed to open from nearly all of the visible monitoring nodes. The named sites are Science.gov, OSTI.gov, which belongs to the Department of Energy (DOE), and EFTPS.gov, the federal tax payment system [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":5108,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[2627,1344,1184,29,1956,1188,773,14,2083,2630,21,1648,1664,2628,2629,1649,749,2381,60,2626,2631,1256,2007,2072,1263,2067,1245,1395,1160,2090],"threat_actors":[407],"class_list":["post-5107","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ddos","tag-check-host-2","tag-ciberseguranca","tag-ciberseguridad","tag-cyber-attack","tag-cyberangriff","tag-cybersecurite","tag-cybersecurity-news","tag-ddos-attack","tag-ddos","tag-eftps","tag-hacktivist","tag-keamanan-siber","tag-keselamatan-siber","tag-osti-gov","tag-science-gov","tag-serangan-ddos","tag-server-killers","tag-siber-guvenlik","tag-threat-intelligence","tag-us-government-websites","tag-2631","tag-1256","tag-2007","tag-2072","tag-1263","tag-2067","tag-1245","tag-1395","tag-1160","tag-2090","threat_actor-server-killers"],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/5107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/comments?post=5107"}],"version-history":[{"count":4,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/5107\/revisions"}],"predecessor-version":[{"id":5116,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/5107\/revisions\/5116"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media\/5108"}],"wp:attachment":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media?parent=5107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/categories?post=5107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/tags?post=5107"},{"taxonomy":"threat_actor","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors?post=5107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}