Cloudflare blocks largest recorded DDoS attack peaking at 3.8Tbps

Share:

During a distributed denial-of-service campaign targeting organizations in the financial services, internet, and telecommunications sectors, volumetric attacks peaked at 3.8 terabits per second, the largest publicly recorded to date. The assault consisted of a “month-long” barrage of more than 100 hyper-volumetric DDoS attacks flooding the network infrastructure with garbage data.

In a volumetric DDoS attack, the target is overwhelmed with large amounts of data to the point that they consume the bandwidth or exhaust the resources of applications and devices, leaving legitimate users with no access.

Asus routers, MikroTik devices, DVRs, and web servers

Many of the attacks aimed at the target’s network infrastructure (network and transport layers L3/4) exceeded two billion packets per second (pps) and three terabits per second (Tbps).

According to researchers at internet infrastructure company Cloudflare, the infected devices were spread across the globe but many of them were located in Russia, Vietnam, the U.S., Brazil, and Spain.

Origin of the 3.8 DDoS attack
DDoS packets delivered from all over the world
source: Cloudflare

The threat actor behind the campaign leveraged multiple types of compromised devices, which included a large number of Asus home routers, Mikrotik systems, DVRs, and web servers.

Cloudflare mitigated all the DDoS attacks autonomously and noted that the one peaking at 3.8 Tbps lasted 65 seconds.

Largest volumetric DDoS attack peaked at 3.8Tbps
Largest publicly recorded volumetric DDoS attack peaking at 3.8Tbps

The researchers say that the network of malicious devices used mainly the User Datagram Protocol (UDP) on a fixed port, a protocol with fast data transfers but which does not require establishing a formal connection.

Previously, Microsoft held the record for defending against the largest volumetric DDoS attack of 3.47 Tbps, which targeted an Azure customer in Asia.

Typically, threat actors launching DDoS attacks rely on large networks of infected devices (botnets) or look for ways to amplify the delivered data at the target, which requires a smaller number of systems.

In a report this week, cloud computing company Akamai confirmed that the recently disclosed CUPS vulnerabilities in Linux could be a viable vector for DDoS attacks.

After scanning the public internet for systems vulnerable to CUPS, Akamai found that more than 58,000 were exposed to DDoS attacks from exploiting the Linux security issue.

More testing revealed that hundreds of vulnerable “CUPS servers will beacon back repeatedly after receiving the initial requests, with some of them appearing to do it endlessly in response to HTTP/404 responses.”

These servers sent thousands of requests to Akamai’s testing systems, showing significant potential for amplification from exploiting the CUPS flaws.

Ionut Ilascu

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:18 am, Jan 31, 2025
weather icon 4°C
L: 2° | H: 5°
light rain
Humidity: 87 %
Pressure: 1025 mb
Wind: 5 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0.75 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:40 am
Sunset: 4:47 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
2° | 5°°C 1 mm 100% 8 mph 92 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 7°°C 0 mm 0% 7 mph 83 % 1030 mb 0 mm/h
Sun Feb 02 9:00 pm
weather icon
2° | 8°°C 0 mm 0% 6 mph 78 % 1026 mb 0 mm/h
Mon Feb 03 9:00 pm
weather icon
2° | 9°°C 0 mm 0% 8 mph 86 % 1027 mb 0 mm/h
Tue Feb 04 9:00 pm
weather icon
6° | 10°°C 0 mm 0% 12 mph 94 % 1028 mb 0 mm/h
Today 6:00 am
weather icon
4° | 4°°C 1 mm 100% 7 mph 89 % 1024 mb 0 mm/h
Today 9:00 am
weather icon
5° | 6°°C 1 mm 100% 8 mph 90 % 1023 mb 0 mm/h
Today 12:00 pm
weather icon
7° | 7°°C 0.8 mm 80% 5 mph 88 % 1023 mb 0 mm/h
Today 3:00 pm
weather icon
8° | 8°°C 0 mm 0% 5 mph 80 % 1024 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 4 mph 92 % 1026 mb 0 mm/h
Today 9:00 pm
weather icon
6° | 6°°C 0 mm 0% 5 mph 92 % 1028 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 5 mph 83 % 1029 mb 0 mm/h
Tomorrow 3:00 am
weather icon
6° | 6°°C 0 mm 0% 6 mph 76 % 1029 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,233.73
-0.47%
Ethereum(ETH)
€3,116.18
2.23%
XRP(XRP)
€2.97
-0.54%
Tether(USDT)
€0.96
0.02%
Solana(SOL)
€227.43
-0.49%
USDC(USDC)
€0.96
0.01%
Dogecoin(DOGE)
€0.315273
-1.20%
Shiba Inu(SHIB)
€0.000018
0.17%
Pepe(PEPE)
€0.000013
1.38%
Scroll to Top