[HN Gopher] Azure hit by 15 Tbps DDoS attack using 500k IP addre...
       ___________________________________________________________________
        
       Azure hit by 15 Tbps DDoS attack using 500k IP addresses
        
       https://techcommunity.microsoft.com/blog/azureinfrastructure...
        
       Author : speckx
       Score  : 127 points
       Date   : 2025-11-17 17:39 UTC (5 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | ChrisArchitect wrote:
       | Source:
       | https://techcommunity.microsoft.com/blog/azureinfrastructure...
        
         | dang wrote:
         | Switched above. Thanks!
        
           | shoddydoordesk wrote:
           | FWIW I think this is a bad practice.
           | 
           | The Microsoft article reads like a corporate press release.
           | The original link contained additional pertinent information
           | and research which is good for discussion.
        
             | dang wrote:
             | OK, I've swapped them back. Thanks!
             | 
             | The principles here are clear: we prefer the best third-
             | party article to corporate press releases*, but at the same
             | time we don't want blogspam (i.e. ripoffs that don't add
             | anything interesting).
             | 
             | * https://hn.algolia.com/?dateRange=all&page=0&prefix=true&
             | sor...
        
       | TZubiri wrote:
       | We should make residential proxies illegal
        
         | teeray wrote:
         | ...and suddenly no one is allowed to VPN back through their
         | home router.
        
         | dongttebayo wrote:
         | We really shouldn't - this seems like perhaps one of the worst
         | ideas one could propose in an era of rising authoritarian rule.
         | Seems like a bad time to be putting silly restrictions on how
         | folks route their traffic.
        
           | derwiki wrote:
           | Tinfoil hat says it's the gov't doing it for those reasons /s
        
             | meowface wrote:
             | I will disregard your cowardly "/s" and say: no, I bet it
             | isn't.
        
           | TZubiri wrote:
           | ok greenie
        
         | jeroenhd wrote:
         | Making them illegal seems far-fetched, but at this point
         | something like email blacklists but for web services is
         | becoming inevitable.
         | 
         | At the moment, that's what Cloudflare is doing. They're just
         | not obvious enough, leading to people on forums (and here)
         | asking "why do I constantly need to fill out captchas to enter
         | websites".
        
         | kachapopopow wrote:
         | breaking the law by using wireguard to access my home network,
         | hmm, great idea.
        
           | TZubiri wrote:
           | Ok, I'll be a bit more specific, banning businesses and the
           | trade of proxies that are purposefully marked as residential,
           | in order to evade firewall blocks, and even to evade proxy
           | blocks.
           | 
           | You gotta draw the line in the sand somewhere, VPNs are
           | already morally dubious, but if you ban the most shady of
           | VPNs, residential proxies, then you can at least guarantee
           | service providers the right to deny service to proxy users,
           | while allowing proxy users to use the proxy everwhere they
           | are welcome in.
        
             | kachapopopow wrote:
             | yah, but how else am I going to create millions of youtube
             | accounts to spam sex bot ads >:(
             | 
             | on a more serious note, it's just not really possible since
             | most residential proxy sites are botnets :)
        
       | drcongo wrote:
       | Imagine how much of that traffic was just the bots following the
       | endless redirects.
        
         | siva7 wrote:
         | Those redirects would crash Azure, i'm betting a grand
        
       | dang wrote:
       | Related. Others?
       | 
       |  _Cloudflare scrubs Aisuru botnet from top domains list_ -
       | https://news.ycombinator.com/item?id=45857836 - Nov 2025 (34
       | comments)
       | 
       |  _Aisuru botnet shifts from DDoS to residential proxies_ -
       | https://news.ycombinator.com/item?id=45741357 - Oct 2025 (59
       | comments)
       | 
       |  _DDoS Botnet Aisuru Blankets US ISPs in Record DDoS_ -
       | https://news.ycombinator.com/item?id=45574393 - Oct 2025 (142
       | comments)
        
       | alpb wrote:
       | Funny enough just got an error trying to reach to the blog
       | Proxy Error             The proxy server received an invalid
       | response from an upstream server.             The proxy server
       | could not handle the request             Reason: Error reading
       | from remote server
        
       | bluedino wrote:
       | IoT is just wave after wave of unsecure devices. There's gotta be
       | a better way.
        
         | rdtsc wrote:
         | The "S" in IoT stands for "security".
        
           | Razengan wrote:
           | Internet of Thingsecurity?
        
         | heresie-dabord wrote:
         | > There's gotta be a better way.
         | 
         | Until then... There's gonna be a bigger wave.
        
         | kachapopopow wrote:
         | fun fact, part of the reason this botnet exists is because
         | europe required the ability to install security updates
         | unattended that you cannot disable and they compromised one of
         | the servers that had the capability to push these updates
         | compromising hundreds of thousands of routers.
        
           | Razengan wrote:
           | Wait when was this?? Did it fly under the news??
        
             | kachapopopow wrote:
             | it's one of the (i believe) hundreds (at this point) of
             | zero-days that is used to build this botnet, at this point
             | they are using funds that they get from selling this botnet
             | to purchase new zero days
        
           | cyberpunk wrote:
           | That's really impressive finger pointing.
           | 
           | If the vendor can't even secure their update server; how long
           | do you think it would be until some RCE on these 100k un-
           | patchable routers gets exploited?
           | 
           | The only people to blame for this is the vendor, and they
           | failed on multiple levels here. It's not hard to sign a
           | firmware, or even just fetch checksums from a different site
           | than you serve the files from...
        
             | kachapopopow wrote:
             | the problem is that these laws just make the problem bigger
             | - instead of having to compromise 100 thousand routers they
             | can just compromise a single update server from a vendor
             | that doesn't care about security.
             | 
             | the fallout is some companies losing their revenue:
             | https://status.neoprotect.net/ and other headaches for
             | people all over the world
        
       | esafak wrote:
       | Is this Aisuru growing? How can it be dismantled?
        
         | SLWW wrote:
         | Yes.
         | 
         | Only way is to secure your IoT devices/routers/cameras/etc.
        
           | esafak wrote:
           | Through personal responsibility? That is not scalable; look
           | at how many compromised devices there are. We need a better
           | solution as an industry.
        
             | rollcat wrote:
             | Yep. Manufacturers / distributors should be held
             | responsible. Aligning the incentives is half the battle.
        
       | dainiusse wrote:
       | /sarcasm Another ai crawler...
        
         | m00x wrote:
         | Anthropic agent went a little haywire on the tool use
        
       | supportengineer wrote:
       | I will never understand why there isn't an international law
       | enforcement agency with teeth, which can get rid of the bad
       | actors.
        
         | trollbridge wrote:
         | I mean, America can't do anything about scam phone calls aimed
         | at seniors who forge caller ID of local hospitals.
        
           | morkalork wrote:
           | Can't or won't?
        
             | trollbridge wrote:
             | I've decided there isn't a difference.
        
           | lossyalgo wrote:
           | As alluded to by morkalork, they definitely could if they
           | wanted to, as the (most? of the) rest of the world doesn't
           | seem to have this problem. As long as spammers keep paying
           | telecoms & no law(s) forbidding this exist, it will continue.
           | 
           | edit: grammar
        
             | toast0 wrote:
             | > As long as spammers keep paying telecoms & no law(s)
             | forbidding this exist, it will continue.
             | 
             | That's the trick. A lot of countries bill calls to cell
             | phones at 10 cents a minute; in the US, calling is near
             | zero cost. The US makes a great market for scammers to
             | target because of low operating costs, penetration of
             | globally usable payment cards, minimal language diversity.
             | 
             | Of course, these scams are forbidden by law, but that
             | doesn't change the economics. Very few scam shops get
             | busted; especially when most of them run from outside the
             | US. STIR/SHAKEN helps a bit, but not much... without a
             | effective mechanism to report unwanted calls that leads to
             | those callers being ejected from the network as well as
             | ejecting providers that are unresponsive to reports,
             | there's not really hope of progress.
        
         | m00x wrote:
         | How would you even enforce this if the offending country
         | doesn't agree?
        
           | dijit wrote:
           | Limit their upstream connection to the rest of the internet
           | via allied countries.
           | 
           | Literally the same as economic sanctions. The internet is a
           | network of peers "trading" bits and bytes after all.
        
             | m00x wrote:
             | This won't do anything. The attacks are not from the
             | offending countries they're from botnets of compromised
             | devices.
             | 
             | North Korea doesn't care if you limit their internet they
             | already allow people to go outside their own.
        
               | dijit wrote:
               | perfect, then we just nullroute at source with Flowspec,
               | even if we change the goalposts a thousand times in this
               | thread there does exist a technical solution to this
               | problem.
               | 
               | Just not enough economic or political incentive to pay
               | for it.
        
             | immibis wrote:
             | America already limits its upstream to China and Russia
             | through a private companies such as Cloudflare and
             | Spamhaus. It's often the case that for Chinese users
             | seeking to escape censorship, once they've worked their way
             | through the Chinese Great Firewall, they find themselves in
             | front of the American one.
        
         | morkalork wrote:
         | I'm sure you could come up with at least few ideas why it
         | hasn't happened
        
         | Hikikomori wrote:
         | America gonna allow someone else to regulate them?
        
         | Thaxll wrote:
         | Because it's not technicaly possible, I mean we're on HN, we
         | all know how internet works.
        
           | dijit wrote:
           | You should talk to a network engineer before making claims
           | like this. There are mechanisms to curtail DDOS attacks at
           | origin.
           | 
           | For a few reasons (political, economical) there's little will
           | to enact them, these attacks are so few and far between and
           | you can pay your way out of them in most cases, so the
           | incentives aren't there for ISPs (whom are a commodity judged
           | primarily on price and bandwidth)
        
             | m00x wrote:
             | How exactly would you keep the origin from sending a
             | command to a botnet?
        
               | dijit wrote:
               | you don't stop the message _to_ the botnet, thats
               | impossible:
               | 
               | You detect the behaviour _downstream_ and send a signal
               | to the ISP that there is traffic that needs to he rate
               | limited.
               | 
               |  _One_ mechanism for this is called RTBH (Remote
               | Triggered BlackHole) which relies on community tagged
               | prefixes of addresses exceeding rate limited to be
               | blackholed from forwarding traffic further in to the
               | internet.
               | 
               | There's also things like flowspec but a _lot_ of things
               | rely on proper trust between ASNs.
        
               | Thaxll wrote:
               | How do you know where it comes from, if they use UDP and
               | change the src of the packets.
        
               | toast0 wrote:
               | The Microsoft blog suggests there was miminal source
               | spoofing (although I don't know how they determine that).
               | But if you can't trust the IP source, packet samples from
               | your border router should indicate which upstream is
               | sending those packets ... then you ask them to find the
               | source... eventually you'll get somewhere ... but when
               | the sources are distributed, it's not so helpful to find
               | the source, unless there's a mechanism to stop the source
               | from sending it.
               | 
               | When I was running servers that would routinely attract
               | DDoSed at ~ 10 Gbps, I ended up always running a low
               | sample rate packet capture. Anytime I noticed a DDoS, I
               | could go and look at the packets. If you've got
               | connectivity to sink and measure 15 Tbps of DDoS, you can
               | probably influence your providers to take some sampled
               | packet captures and look at them too.
               | 
               | Even without clear information from packet captures, 15
               | Tbps is going to make an impact on traffic graphs, and
               | you can figure out sources from those, although it might
               | be a bit tricky because the attack duration was reported
               | at only 40 seconds, so if someone only has hourly stats,
               | it might be too small to be noticed; but once a minute
               | stats are pretty common.
        
               | Fabricio20 wrote:
               | IP spoofing is pretty uncommon nowadays because everyone
               | has anti-spoofing mechanisms in place and most ASNs often
               | don't forward spoofed addresses outbound.
               | 
               | But as the sibling mentioned, even with spoofing, you can
               | still follow the packet trail from your border routers
               | upstream. I think the main thing we are lacking is just
               | responsibility on the ISP side, if someone reaches out
               | complaining that half of your customers are sending ddos
               | attacks, maybe you need to do something about it. Most of
               | these huge attacks are compromised routers or IoT devices
               | (remember Mirai Botnet?).
        
               | esseph wrote:
               | This is clearly not true, or the CAIDA anti-spoofer
               | project wouldn't exist.
               | 
               | https://spoofer.caida.org/summary.php
        
               | esseph wrote:
               | It's not that simple and hasn't been for awhile.
               | 
               | There's layer upon layer of relays now, and meshed C2C
               | networks.
               | 
               | Lots of DNS fastflux too
        
           | SirMaster wrote:
           | I heard it's a series of tubes.
        
         | Y_Y wrote:
         | The international organisation for stopping wars, human
         | trafficking, money laundering, drug distribution etc. however
         | capable they might be, haven't managed to stamp out any of
         | those things.
         | 
         | I'd say a putative UN NetWatch would suffer from the same
         | issues of funding and corruption and politics, but still we
         | might have something better than this wild west lawlessness.
        
           | halapro wrote:
           | > have something better than this wild west lawlessness.
           | 
           | Careful what you wish for. Before you know it you can't have
           | an IP without your ID.
        
             | immibis wrote:
             | This is already the case in Germany and many other
             | countries. Same for phone numbers. On the other hand, I get
             | no spam calls, and I can't access the sites on
             | https://cuiiliste.de/domains - censorship is amazing.
        
               | bak3y wrote:
               | Yes, surely the German government telling it's people
               | what to do has never gotten them in trouble in the
               | past...
        
           | c0balt wrote:
           | > putative UN NetWatch
           | 
           | But who will suppress attempts to go beyond the blackwall
           | then?
        
         | sva_ wrote:
         | Since this is a distributed attack, I'm not really sure how
         | that enforcement would look like? Am I missing something, are
         | all these bots/zombies easily selectable and blockable?
        
           | toast0 wrote:
           | Investigative powers should be able to at least find and
           | seize the command and control servers, and hopefully track
           | down people operating the command and control servers.
           | 
           | Some sort of international clearing house for ISPs to help
           | identify and sequester compromised customers might be nice,
           | too; but that doesn't need law enforcement powers; and maybe
           | it already exists?
        
         | poszlem wrote:
         | Perhaps because, in many cases, the very governments
         | responsible for enforcing it include the bad actors themselves.
        
         | Aurornis wrote:
         | International DDoS busts and arrests do happen all the time.
         | 
         | Law enforcement takes time. The perpetrators of these attacks
         | aren't hanging out in the open with their full names shielded
         | only by the hope that their country won't extradite for
         | political favor.
         | 
         | By the time the perpetrators are identified and a case is
         | built, getting them charged isn't bottlenecked on the lack of
         | an international agency. Any international law enforcement
         | agency would be beholden to each country's own political wills
         | and ideals, meaning any "teeth" they had would be no more
         | effective than what we currenly have for extraditing people or
         | cooperating with foreign police organizations.
        
         | kachapopopow wrote:
         | the real reason why these are a problem in the first place is
         | because of cgnat and transit providers not implementing
         | flowspec.
         | 
         | but these bad actors are not possible to track down in the
         | first place since internet is unfortunately decentralized and
         | things as simple as transactions submitted to bitcoin or
         | etherium blockchain can be used as c&c
        
         | zipy124 wrote:
         | Because countries benefit from conducting cyber warfare, the
         | most publicised of are north Korea and Russia which have large
         | state sponsored hacking groups.
        
         | mihaaly wrote:
         | Legal systems are so convoluted and so colossally heterogenous
         | - also very protective of their ways - around the globe that
         | miniscule collaborations require grandiose efforts to initiate
         | and maintain. No chance these fast paced adversaries will be
         | caught by the interplay of several dozens of reluctant dinosaur
         | legal systems.
         | 
         | Tangential: once I was targeted by a pretty primitive scam.
         | More than 10 years ago (after someone I love was naive and
         | inexperienced, having a medium amount stolen in a sensitive and
         | stressful time of this person's life). I recognised fast and
         | having time and will I sarted to play along, pretending I bite
         | the bait. Collecting info while acting. In parallel trying to
         | connect local and international authorities to report an
         | ongoing scam effort. I believe I tried 4 organizations in 3
         | different countries apparently involved, I believe one was
         | dedicated to online scams, also trying to warn Western Union,
         | they are about to be used for scam. I even went personally to a
         | police station locally to get some advice on how to assist
         | catching the criminals. Since all I encountered insisted to
         | report my damages, so they could start an investigation on an
         | actual loss happened, I furiously gave up and decided whenever
         | I will be having financial trouble I will invest my efforts in
         | scamming others. No-one cares catching those in act! So the
         | thugs can be incredibly bold and dumb, like the one I
         | encountered, it is no effort doing better.
        
         | miohtama wrote:
         | It's national interest of China and Russia to see the West to
         | fail. Why would they co-operate? They are willing to murder
         | people, West and their own, so "law" enforcement means a bit
         | different in international context.
        
         | bsder wrote:
         | If we were all running IPv6, we could just block this crap.
         | 
         | But here we are in 2025 still running IPv4 with CGNAT, so we
         | can't.
        
         | dylan604 wrote:
         | Because every single nation would have to sign on to it
         | allowing said agency to ignore sovereignty of each nation to
         | come in and do their policing.
         | 
         | You'd also need to have every country not actively involved in
         | these types of schemes yet we know some governments are
         | directly benefiting from the scams/theft their citizens are
         | perpetrating.
         | 
         | You'd also need to have every country think the things you want
         | to police against are wrong. Again, we know that's just not
         | true.
        
       | shoddydoordesk wrote:
       | > it suddenly ballooned in size in April 2025 after its operators
       | breached a TotoLink router firmware update server and infected
       | approximately 100,000 devices
       | 
       | This is scary. Everyone lauds open source projects like OpenWRT
       | but... who is watching their servers?
       | 
       | I imagine you can't run an army of security people on donations
       | and a shoestring budget. Does OpenWRT use digital signing to
       | mitigate this?
        
         | sam_lowry_ wrote:
         | This is exactly why OpenWRT has no unattended updates by
         | default )
        
           | shoddydoordesk wrote:
           | You are dismissing the seriousness of this. Their package
           | manager is widely used. One would only need to compromise
           | their build servers to wreak havoc.
           | 
           | Didn't they have a vulnerability in their firmware download
           | tool like a minute ago?
           | 
           | The difference between OpenWRT and Linux distros is the
           | amount of testing and visibility. OpenWRT is loaded on to
           | residential devices and forgotten about, it doesn't have
           | professional sysadmins babysitting it 24/7.
           | 
           | Remember the xz backdoor was only discovered because some
           | autist at Microsoft noticed a microsecond difference in
           | performance testing.
        
             | jacobgkau wrote:
             | I'm confused why you're so honed in on OpenWRT as a third-
             | party open-source project here when the vulnerability you
             | quoted (TotoLink) was the official firmware update server
             | of a brand of devices.
             | 
             | Is it "scary" to think about OpenWRT potentially getting
             | hacked? If you get scared by theoretical possibilities in
             | software, sure. Is it relevant? Not exactly. Are companies'
             | official servers more secure than an open-source project's
             | servers? In this case, apparently not.
        
               | danudey wrote:
               | What's scary is that OpenWRT is a project created by
               | people who wanted a better solution than what was out
               | there, and are therefore largely driven by a desire to
               | create a good product.
               | 
               | Meanwhile, corporations are driven entirely by profit
               | motive, so as long as it's more expensive to be vigilant
               | about security than it is to be lax about it they will
               | never improve.
               | 
               | Until companies which produce (and do not update)
               | vulnerable equipment are penalized (e.g. charged with
               | criminal negligence) for DDoS attacks using their
               | hardware then the open-source projects are going to
               | continue to be far more trustworthy and less vulnerable
               | than corporations which mass-produce the cheapest
               | hardware they can and then designating it as obsolete and
               | unsupported as fast as possible to force more updates.
        
         | whatshisface wrote:
         | As always, hundreds watch the open repositories, maybe one
         | watches a company's build servers, if they're lucky. :-)
        
           | TylerE wrote:
           | Hundreds watch, but how closely?
           | 
           | Plenty of stories of fairly major projects having evil
           | commits snuck in that remain for months.
        
         | immibis wrote:
         | Digital signing wouldn't defend you from a compromised build
         | server.
        
           | mbilker wrote:
           | What in that act says OpenWrt would be made illegal? If
           | anything, OpenWrt would roll out automated security updates
           | for a supported branched release to comply with these
           | regulations.
           | 
           | Also, if you actually read it, there are exceptions for open
           | source software!
        
             | majorchord wrote:
             | OP claims almost daily that some benign thing is actually
             | illegal but practically never provides any useful proof
             | when asked.
             | 
             | (please prove me wrong, Alex)
        
         | tempest_ wrote:
         | I don't follow.
         | 
         | > run an army of security people
         | 
         | Do you think these private companies do this? They don't. They
         | pay as little as humanly possible to cover their ass.
         | 
         | Botnets comprised of compromised routers is common and
         | commercial/consumer routers are a far juicer target than
         | openwrt.
        
         | nine_k wrote:
         | Why, OpenWRT firmware and packages are both signed, of course.
         | You can manually and independently check the image signature
         | before flashing an update.
         | 
         | The build infrastructure is, of course, a juicy target: infect
         | the artifact after building but before signing, and pwn
         | millions of boxes before this is detected.
         | 
         | This is why bit-perfect reproducible builds are so important.
         | OpenWRT in particular have that:
         | https://openwrt.org/docs/guide-developer/security#reproducib...
        
           | tetha wrote:
           | Bit-Reproducible infrastructure could also result in some of
           | the wildest build distribution architectures if you think
           | about it. You could publish sources and have people register
           | like in APT mirrors to provide builds, and at the end of the
           | day, the build from the largest bit-equal group is published.
           | 
           | I do see the Tor-Issue - a botnet or a well-supplied
           | malicious actor could just flood it. And if you flip it - if
           | you'd need agreement about the build output, it could also be
           | poisoned with enough nodes to prevent releases for a critical
           | security issue. I agree, I don't solve all supply chain
           | issues in one comment :)
           | 
           | But that in turn could be helped with reputation. Maybe a
           | node needs to supply 6 months of perfect builds - for testing
           | as well - to become eligible. Which would be defeated by
           | patience, but what isn't? It'd just have to be more annoying
           | to breach the distributed build infrastructure than to plant
           | a malicious developer.
           | 
           | This combination of reproducible, deterministic builds, tests
           | across a number of probably-trustworthy sources is quite
           | interesting, as it allows very heavy decentralization. I
           | could just run an old laptop or two here to support. And then
           | come compromise hundreds of these all across the world.
        
             | smt88 wrote:
             | The distribution system you're describing exists and has
             | been in use for decades. You just distribute the build
             | using bittorrent.
        
             | charcircuit wrote:
             | >It'd just have to be more annoying to breach the
             | distributed build infrastructure than to plant a malicious
             | developer.
             | 
             | It really wouldn't. You don't even need a powerful build
             | server since you can mirror whatever someone else built.
             | You can also buy / hack nodes of existing trusted people.
        
       | null_deref wrote:
       | I don't mean to cast any doubt, but are those short articles the
       | standard, or why was there almost no data provided?
        
       | sva_ wrote:
       | I feel like posting the traffic output of the network might not
       | be a great idea because they might do these attacks on purpose to
       | market their network's capability.
        
         | kachapopopow wrote:
         | it's an open secret at that point and the attacks are far
         | larger than that are causing congestion world-wide from the
         | time they wake up to the time they go to sleep.
        
       | Y_Y wrote:
       | _Cui bono?_
       | 
       | There is a big (opportunity) cost to this kind of thing, How is
       | this worthwhile for anyone? I assume that its's not just a
       | competitor. Is it really worth <insert evil country>'s time to
       | temporarily upset one of of three big cloud providers? Is there a
       | ransom behind the scenes?
        
         | kachapopopow wrote:
         | nope, there's really no cost to it - they've been hitting with
         | attacks double or even triple the size towards random minecraft
         | hosts for months now.
        
       | imglorp wrote:
       | > it targeted a single endpoint in Australia.
       | 
       | It would really help to understand why attack one endpoint with
       | "the largest DDoS attack ever observed in the cloud". If it was
       | important, it would be redundant in its CDN. Who paid for this
       | attack and what did they gain?
        
         | kachapopopow wrote:
         | we were getting hit with attacks like this daily at some point
         | and were forced to use cloudflare magic transit it's pretty
         | random and you shouldn't read too deep into it as nearly every
         | anti-ddos solution, host and isp has been hit with this botnet
         | by now.
        
           | estearum wrote:
           | but why? For fun?
        
             | kachapopopow wrote:
             | yep, there's no consistency to their actions - basically
             | hit a target and keep it down for as long as possible
             | causing heavy business loss. to my knowledge none of the
             | target servers have ever received a ransom request.
        
             | toast0 wrote:
             | I used to run servers for a very popular service. I'm 99%
             | sure people DDoSed our www for lolz and also to kick the
             | tires on DDoS as a service vendors. We would get DDoS on a
             | pretty regular basis, for exactly 90 seconds, +/- a few
             | nodes that had bad clock sync and were 2 seconds off; which
             | was exactly what you get from a free trial at DDoS as a
             | service. I feel like we got a ransom request like once; but
             | I can't remember if it actually corresponded to an attack,
             | if it did, I don't think it was consequential.
             | 
             | Thankfully, it was almost always targetted at our www
             | servers, which were not important for our service. _Very_
             | occasionally, we 'd get hit on the machines that we
             | actually ran our service on, but between the consistent
             | DDoS on www, and our own self-inflicted DDoS from defects
             | in the client code we wrote for our users, our service was
             | well prepared... if the DDoS went over line rate for the
             | server, our hosting provider would null route it [1], but
             | otherwise, we could manage line rate of udp reflection or
             | tcp syn floods and what have you. From what I could tell,
             | most attackers didn't retarget to our other servers when
             | one got null routed.
             | 
             | [1] They did try a DDoS scrubbing service, but having our
             | servers behind the scrubber was way worse than just null
             | routing. Maybe the scrubbing could have been tuned, but as
             | it was, it was better for us to just have the attacked
             | servers lose connectivity to the public network.
        
               | Razengan wrote:
               | > _self-inflicted defects_
               | 
               | is what I'll call bugs from now
        
             | Fabricio20 wrote:
             | As someone on the receiving end of these, I've yet to
             | receive any explanation. Every other week we see the most
             | basic of attacks against our infrastructure (http floods -
             | GET / - for example), with no specific goal in mind and we
             | never received any threats. I can only assume it's some
             | disgruntled user or maybe a competitor, but it could also
             | just be stray bullets. I don't know who used these IPs
             | before us, though it's been several years we've owned them.
             | Who knows.
        
         | cookiengineer wrote:
         | You are assuming that DDoS is signal. It's not, it's the noise.
         | 
         | The idea of DDoS for hire is to bury your own tracks in as much
         | network requests as possible, so that the other side is
         | overwhelmed processing (or even storing) that dataset and won't
         | find out what the real target was.
         | 
         | That's literally the strategy of APT28/29.
        
       | perfmode wrote:
       | A DDoS attack is often used to distract a company's security
       | team. While the security staff is scrambling to get the website
       | back online, the attackers use the chaos to conduct a more
       | serious, stealthy attack.
        
         | mihaaly wrote:
         | It was interesting to read that the record breaking attack
         | caused no glitch whatsoever in the service MS provides. Which
         | is so slow normally that I start to wonder if that is a
         | strategy, having headroom for these kind of situations, no-one
         | realizes slowdown when it is already slow. ;)
         | 
         | This is just a crazy thought, tangential to what are happening
         | during an attack.
        
       | averageRoyalty wrote:
       | > This attack lasted only 40 seconds but was roughly equivalent
       | to streaming one million 4K videos simultaneously.
       | 
       | Who is this for? Is there anyone reading the article that can't
       | grasp what a terrabit is but can somehow conceptualise one
       | million 4k videos streaming simultaneously? I don't think anyone
       | sits in that venn diagram.
        
       | haunter wrote:
       | This is what I don't get
       | 
       | >The Aisuru DDoS botnet operates as a DDoS-for-hire service with
       | restricted clientele; operators have reportedly implemented
       | preventive measures to avoid attacking governmental, law
       | enforcement, military, and other national security properties.
       | Most observed Aisuru attacks to date appear to be related to
       | online gaming.
       | 
       | https://www.netscout.com/blog/asert/asert-threat-summary-ais...
       | 
       | So why? Like why would someone pay to take a game down? I see
       | this all over reddit with different games but I just don't get
       | the point. What's the benefit of taking down an online game for a
       | couple of hours.
        
         | denkmoon wrote:
         | Mad salt. Imagine a fully grown man having a toddler tantrum.
         | "If I can't play/win/get my way, nobody can" type mentality.
         | It's also a method of coercion. Give me mod status or I'll DDOS
         | your server and destroy your community.
         | 
         | The other half comes from sever operators ddosing their
         | competition. There is a lot of money to be made from paid
         | cosmetics, ranks, moderator (demi-tyrant) status, etc on custom
         | servers.
        
         | manquer wrote:
         | Probably it has to do with all the gambling sites associated
         | with gaming not the games itself.
         | 
         | Taking a competitor offline for a few hours is a lot of money
         | in a market business I expect.
         | 
         | there seems to be lot of weird stuff going on with gaming
         | casinos the recent CoffeeZilla episode comes to mind, so
         | wouldn't be surprised if not botnets are used
        
         | iknowstuff wrote:
         | They get banned for trolling, griefing, cheating, breaking
         | rules etc. and want revenge. Every game operator has to deal
         | with idiots like this
        
           | AmbroseBierce wrote:
           | Yeah, every single ban in every single game is 100% justified
           | and game operators never make mistakes when exercising such
           | punishment.
        
             | iknowstuff wrote:
             | yeah bud if the person ends up ddosing I'm 100% certain
             | their ban was justified lol
        
             | water-your-self wrote:
             | At the end of the day, at least for silly private servers,
             | you are always welcome to build it yourself. Theres much to
             | learn in doing that.
        
         | bstsb wrote:
         | the ddos market has been somewhat centered around gaming for a
         | while now, mainly to take down game server competition, or as
         | an attempt to sell big players on "ddos protection" services.
         | 
         | well, gaming and Krebs's blog:
         | https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with...
        
         | Onawa wrote:
         | It depends on the game, but for those with some kind of
         | marketplace or transferable currency, I'm guessing market
         | manipulation is one possible reason.
         | 
         | For other games, maybe trying to interrupt some time limited
         | event or tournament. Going all the way down the rabbit hole, if
         | you're not already familiar take a look at how crazy things get
         | in a game like EVE: Online.
         | 
         | Then of course there are the bored trolls and/or people who
         | feel wronged by the game's developers or other players.
        
         | zaphirplane wrote:
         | Depends on How much does it cost to hire it
        
         | hobs wrote:
         | Most of the time its just blackmail/extortion - pay us or we do
         | the thing.
        
         | ddtaylor wrote:
         | > So why? Like why would someone pay to take a game down? I see
         | this all over reddit with different games but I just don't get
         | the point. What's the benefit of taking down an online game for
         | a couple of hours.
         | 
         | Most of the time crime groups are running extortion campaigns,
         | amplification campaigns, etc. For example, if a competitor can
         | benefit from them being down you may be able to sell that.
         | Eventually we will probably see the invention of crowd-funded
         | randsomware, where everyone must submit one verification can of
         | crypto to unlock the hacked game servers.
        
       ___________________________________________________________________
       (page generated 2025-11-17 23:00 UTC)