Cloudflare says it stopped the largest HTTPS DDoS attack ever


Cloudflare says that it recently stopped the largest HTTPS DDoS attack ever seen.
Product Manager Omer Yoachimik revealed in a blog post (opens in new tab) that the company automatically detected and mitigated a 26 million request per second (RPS) attack against a customer website using the company’s Free plan.
Such a powerful attack was made possible thanks to threat actors using hijacked virtual machines and servers, rather than Internet of Things (IoT) devices, to send the malicious traffic (opens in new tab), the company said. In total, roughly 5,000 devices were used for the attack, with each endpoint (opens in new tab) generating roughly 5,200 RPS at peak.
Expensive attacks
This goes to show just how dangerous virtual machines and servers are, when used for DDoS attacks, the company says, as other, larger botnets, aren’t capable of mimicking a fraction of this power.
Thirty seconds into the attack, the botnet generated more than 212 million HTTPS requests from more than 1,500 neworks, located in 121 countries. Most requests came from Indonesia, the US, Brazil, and Russia. Some 3% of the attack came through Tor nodes.
The top source networks include French-based OVH (Autonomous System Number 16276), the Indonesian Telkomnet (ASN 7713), the US-based iboss (ASN 137922) and the Libyan Ajeel (ASN 37284), the blog adds.
Cloudflare also said the attack was over HTTPS, making it more expensive in terms of required computational resources, as establishing a secure TLS encrypted connection costs more. Consequently, it also costs more to mitigate it, Cloudflare said. “We’ve seen very large attacks in the past over (unencrypted) HTTP, but this attack stands out because of the resources it required at its scale,” the blog reads.
Large attacks are growing, both in size, and in frequency, Cloudflare warns. Still, they remain short and rapid, as threat actors try to wreak as much havoc as possible, without being spotted.
Audio player loading… Cloudflare says that it recently stopped the largest HTTPS DDoS attack ever seen. Product Manager Omer Yoachimik revealed in a blog post (opens in new tab) that the company automatically detected and mitigated a 26 million request per second (RPS) attack against a customer website using the…
Recent Posts
- Your new favorite teacher might be this AI educator that never loses their patience
- Kia’s next EV is the affordable, long-range EV4 sedan
- Meta’s AI chatbot will soon have a standalone app
- Framework’s Laptop 12 Could Inject New Life Into Budget Portable PCs
- CRKD teamed up with Gibson to make new guitar controllers
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010