[HN Gopher] Azure hit by 15 Tbps DDoS attack using 500k IP addre...
___________________________________________________________________
Azure hit by 15 Tbps DDoS attack using 500k IP addresses
https://techcommunity.microsoft.com/blog/azureinfrastructure...
Author : speckx
Score : 127 points
Date : 2025-11-17 17:39 UTC (5 hours ago)
(HTM) web link (www.bleepingcomputer.com)
(TXT) w3m dump (www.bleepingcomputer.com)
| ChrisArchitect wrote:
| Source:
| https://techcommunity.microsoft.com/blog/azureinfrastructure...
| dang wrote:
| Switched above. Thanks!
| shoddydoordesk wrote:
| FWIW I think this is a bad practice.
|
| The Microsoft article reads like a corporate press release.
| The original link contained additional pertinent information
| and research which is good for discussion.
| dang wrote:
| OK, I've swapped them back. Thanks!
|
| The principles here are clear: we prefer the best third-
| party article to corporate press releases*, but at the same
| time we don't want blogspam (i.e. ripoffs that don't add
| anything interesting).
|
| * https://hn.algolia.com/?dateRange=all&page=0&prefix=true&
| sor...
| TZubiri wrote:
| We should make residential proxies illegal
| teeray wrote:
| ...and suddenly no one is allowed to VPN back through their
| home router.
| dongttebayo wrote:
| We really shouldn't - this seems like perhaps one of the worst
| ideas one could propose in an era of rising authoritarian rule.
| Seems like a bad time to be putting silly restrictions on how
| folks route their traffic.
| derwiki wrote:
| Tinfoil hat says it's the gov't doing it for those reasons /s
| meowface wrote:
| I will disregard your cowardly "/s" and say: no, I bet it
| isn't.
| TZubiri wrote:
| ok greenie
| jeroenhd wrote:
| Making them illegal seems far-fetched, but at this point
| something like email blacklists but for web services is
| becoming inevitable.
|
| At the moment, that's what Cloudflare is doing. They're just
| not obvious enough, leading to people on forums (and here)
| asking "why do I constantly need to fill out captchas to enter
| websites".
| kachapopopow wrote:
| breaking the law by using wireguard to access my home network,
| hmm, great idea.
| TZubiri wrote:
| Ok, I'll be a bit more specific, banning businesses and the
| trade of proxies that are purposefully marked as residential,
| in order to evade firewall blocks, and even to evade proxy
| blocks.
|
| You gotta draw the line in the sand somewhere, VPNs are
| already morally dubious, but if you ban the most shady of
| VPNs, residential proxies, then you can at least guarantee
| service providers the right to deny service to proxy users,
| while allowing proxy users to use the proxy everwhere they
| are welcome in.
| kachapopopow wrote:
| yah, but how else am I going to create millions of youtube
| accounts to spam sex bot ads >:(
|
| on a more serious note, it's just not really possible since
| most residential proxy sites are botnets :)
| drcongo wrote:
| Imagine how much of that traffic was just the bots following the
| endless redirects.
| siva7 wrote:
| Those redirects would crash Azure, i'm betting a grand
| dang wrote:
| Related. Others?
|
| _Cloudflare scrubs Aisuru botnet from top domains list_ -
| https://news.ycombinator.com/item?id=45857836 - Nov 2025 (34
| comments)
|
| _Aisuru botnet shifts from DDoS to residential proxies_ -
| https://news.ycombinator.com/item?id=45741357 - Oct 2025 (59
| comments)
|
| _DDoS Botnet Aisuru Blankets US ISPs in Record DDoS_ -
| https://news.ycombinator.com/item?id=45574393 - Oct 2025 (142
| comments)
| alpb wrote:
| Funny enough just got an error trying to reach to the blog
| Proxy Error The proxy server received an invalid
| response from an upstream server. The proxy server
| could not handle the request Reason: Error reading
| from remote server
| bluedino wrote:
| IoT is just wave after wave of unsecure devices. There's gotta be
| a better way.
| rdtsc wrote:
| The "S" in IoT stands for "security".
| Razengan wrote:
| Internet of Thingsecurity?
| heresie-dabord wrote:
| > There's gotta be a better way.
|
| Until then... There's gonna be a bigger wave.
| kachapopopow wrote:
| fun fact, part of the reason this botnet exists is because
| europe required the ability to install security updates
| unattended that you cannot disable and they compromised one of
| the servers that had the capability to push these updates
| compromising hundreds of thousands of routers.
| Razengan wrote:
| Wait when was this?? Did it fly under the news??
| kachapopopow wrote:
| it's one of the (i believe) hundreds (at this point) of
| zero-days that is used to build this botnet, at this point
| they are using funds that they get from selling this botnet
| to purchase new zero days
| cyberpunk wrote:
| That's really impressive finger pointing.
|
| If the vendor can't even secure their update server; how long
| do you think it would be until some RCE on these 100k un-
| patchable routers gets exploited?
|
| The only people to blame for this is the vendor, and they
| failed on multiple levels here. It's not hard to sign a
| firmware, or even just fetch checksums from a different site
| than you serve the files from...
| kachapopopow wrote:
| the problem is that these laws just make the problem bigger
| - instead of having to compromise 100 thousand routers they
| can just compromise a single update server from a vendor
| that doesn't care about security.
|
| the fallout is some companies losing their revenue:
| https://status.neoprotect.net/ and other headaches for
| people all over the world
| esafak wrote:
| Is this Aisuru growing? How can it be dismantled?
| SLWW wrote:
| Yes.
|
| Only way is to secure your IoT devices/routers/cameras/etc.
| esafak wrote:
| Through personal responsibility? That is not scalable; look
| at how many compromised devices there are. We need a better
| solution as an industry.
| rollcat wrote:
| Yep. Manufacturers / distributors should be held
| responsible. Aligning the incentives is half the battle.
| dainiusse wrote:
| /sarcasm Another ai crawler...
| m00x wrote:
| Anthropic agent went a little haywire on the tool use
| supportengineer wrote:
| I will never understand why there isn't an international law
| enforcement agency with teeth, which can get rid of the bad
| actors.
| trollbridge wrote:
| I mean, America can't do anything about scam phone calls aimed
| at seniors who forge caller ID of local hospitals.
| morkalork wrote:
| Can't or won't?
| trollbridge wrote:
| I've decided there isn't a difference.
| lossyalgo wrote:
| As alluded to by morkalork, they definitely could if they
| wanted to, as the (most? of the) rest of the world doesn't
| seem to have this problem. As long as spammers keep paying
| telecoms & no law(s) forbidding this exist, it will continue.
|
| edit: grammar
| toast0 wrote:
| > As long as spammers keep paying telecoms & no law(s)
| forbidding this exist, it will continue.
|
| That's the trick. A lot of countries bill calls to cell
| phones at 10 cents a minute; in the US, calling is near
| zero cost. The US makes a great market for scammers to
| target because of low operating costs, penetration of
| globally usable payment cards, minimal language diversity.
|
| Of course, these scams are forbidden by law, but that
| doesn't change the economics. Very few scam shops get
| busted; especially when most of them run from outside the
| US. STIR/SHAKEN helps a bit, but not much... without a
| effective mechanism to report unwanted calls that leads to
| those callers being ejected from the network as well as
| ejecting providers that are unresponsive to reports,
| there's not really hope of progress.
| m00x wrote:
| How would you even enforce this if the offending country
| doesn't agree?
| dijit wrote:
| Limit their upstream connection to the rest of the internet
| via allied countries.
|
| Literally the same as economic sanctions. The internet is a
| network of peers "trading" bits and bytes after all.
| m00x wrote:
| This won't do anything. The attacks are not from the
| offending countries they're from botnets of compromised
| devices.
|
| North Korea doesn't care if you limit their internet they
| already allow people to go outside their own.
| dijit wrote:
| perfect, then we just nullroute at source with Flowspec,
| even if we change the goalposts a thousand times in this
| thread there does exist a technical solution to this
| problem.
|
| Just not enough economic or political incentive to pay
| for it.
| immibis wrote:
| America already limits its upstream to China and Russia
| through a private companies such as Cloudflare and
| Spamhaus. It's often the case that for Chinese users
| seeking to escape censorship, once they've worked their way
| through the Chinese Great Firewall, they find themselves in
| front of the American one.
| morkalork wrote:
| I'm sure you could come up with at least few ideas why it
| hasn't happened
| Hikikomori wrote:
| America gonna allow someone else to regulate them?
| Thaxll wrote:
| Because it's not technicaly possible, I mean we're on HN, we
| all know how internet works.
| dijit wrote:
| You should talk to a network engineer before making claims
| like this. There are mechanisms to curtail DDOS attacks at
| origin.
|
| For a few reasons (political, economical) there's little will
| to enact them, these attacks are so few and far between and
| you can pay your way out of them in most cases, so the
| incentives aren't there for ISPs (whom are a commodity judged
| primarily on price and bandwidth)
| m00x wrote:
| How exactly would you keep the origin from sending a
| command to a botnet?
| dijit wrote:
| you don't stop the message _to_ the botnet, thats
| impossible:
|
| You detect the behaviour _downstream_ and send a signal
| to the ISP that there is traffic that needs to he rate
| limited.
|
| _One_ mechanism for this is called RTBH (Remote
| Triggered BlackHole) which relies on community tagged
| prefixes of addresses exceeding rate limited to be
| blackholed from forwarding traffic further in to the
| internet.
|
| There's also things like flowspec but a _lot_ of things
| rely on proper trust between ASNs.
| Thaxll wrote:
| How do you know where it comes from, if they use UDP and
| change the src of the packets.
| toast0 wrote:
| The Microsoft blog suggests there was miminal source
| spoofing (although I don't know how they determine that).
| But if you can't trust the IP source, packet samples from
| your border router should indicate which upstream is
| sending those packets ... then you ask them to find the
| source... eventually you'll get somewhere ... but when
| the sources are distributed, it's not so helpful to find
| the source, unless there's a mechanism to stop the source
| from sending it.
|
| When I was running servers that would routinely attract
| DDoSed at ~ 10 Gbps, I ended up always running a low
| sample rate packet capture. Anytime I noticed a DDoS, I
| could go and look at the packets. If you've got
| connectivity to sink and measure 15 Tbps of DDoS, you can
| probably influence your providers to take some sampled
| packet captures and look at them too.
|
| Even without clear information from packet captures, 15
| Tbps is going to make an impact on traffic graphs, and
| you can figure out sources from those, although it might
| be a bit tricky because the attack duration was reported
| at only 40 seconds, so if someone only has hourly stats,
| it might be too small to be noticed; but once a minute
| stats are pretty common.
| Fabricio20 wrote:
| IP spoofing is pretty uncommon nowadays because everyone
| has anti-spoofing mechanisms in place and most ASNs often
| don't forward spoofed addresses outbound.
|
| But as the sibling mentioned, even with spoofing, you can
| still follow the packet trail from your border routers
| upstream. I think the main thing we are lacking is just
| responsibility on the ISP side, if someone reaches out
| complaining that half of your customers are sending ddos
| attacks, maybe you need to do something about it. Most of
| these huge attacks are compromised routers or IoT devices
| (remember Mirai Botnet?).
| esseph wrote:
| This is clearly not true, or the CAIDA anti-spoofer
| project wouldn't exist.
|
| https://spoofer.caida.org/summary.php
| esseph wrote:
| It's not that simple and hasn't been for awhile.
|
| There's layer upon layer of relays now, and meshed C2C
| networks.
|
| Lots of DNS fastflux too
| SirMaster wrote:
| I heard it's a series of tubes.
| Y_Y wrote:
| The international organisation for stopping wars, human
| trafficking, money laundering, drug distribution etc. however
| capable they might be, haven't managed to stamp out any of
| those things.
|
| I'd say a putative UN NetWatch would suffer from the same
| issues of funding and corruption and politics, but still we
| might have something better than this wild west lawlessness.
| halapro wrote:
| > have something better than this wild west lawlessness.
|
| Careful what you wish for. Before you know it you can't have
| an IP without your ID.
| immibis wrote:
| This is already the case in Germany and many other
| countries. Same for phone numbers. On the other hand, I get
| no spam calls, and I can't access the sites on
| https://cuiiliste.de/domains - censorship is amazing.
| bak3y wrote:
| Yes, surely the German government telling it's people
| what to do has never gotten them in trouble in the
| past...
| c0balt wrote:
| > putative UN NetWatch
|
| But who will suppress attempts to go beyond the blackwall
| then?
| sva_ wrote:
| Since this is a distributed attack, I'm not really sure how
| that enforcement would look like? Am I missing something, are
| all these bots/zombies easily selectable and blockable?
| toast0 wrote:
| Investigative powers should be able to at least find and
| seize the command and control servers, and hopefully track
| down people operating the command and control servers.
|
| Some sort of international clearing house for ISPs to help
| identify and sequester compromised customers might be nice,
| too; but that doesn't need law enforcement powers; and maybe
| it already exists?
| poszlem wrote:
| Perhaps because, in many cases, the very governments
| responsible for enforcing it include the bad actors themselves.
| Aurornis wrote:
| International DDoS busts and arrests do happen all the time.
|
| Law enforcement takes time. The perpetrators of these attacks
| aren't hanging out in the open with their full names shielded
| only by the hope that their country won't extradite for
| political favor.
|
| By the time the perpetrators are identified and a case is
| built, getting them charged isn't bottlenecked on the lack of
| an international agency. Any international law enforcement
| agency would be beholden to each country's own political wills
| and ideals, meaning any "teeth" they had would be no more
| effective than what we currenly have for extraditing people or
| cooperating with foreign police organizations.
| kachapopopow wrote:
| the real reason why these are a problem in the first place is
| because of cgnat and transit providers not implementing
| flowspec.
|
| but these bad actors are not possible to track down in the
| first place since internet is unfortunately decentralized and
| things as simple as transactions submitted to bitcoin or
| etherium blockchain can be used as c&c
| zipy124 wrote:
| Because countries benefit from conducting cyber warfare, the
| most publicised of are north Korea and Russia which have large
| state sponsored hacking groups.
| mihaaly wrote:
| Legal systems are so convoluted and so colossally heterogenous
| - also very protective of their ways - around the globe that
| miniscule collaborations require grandiose efforts to initiate
| and maintain. No chance these fast paced adversaries will be
| caught by the interplay of several dozens of reluctant dinosaur
| legal systems.
|
| Tangential: once I was targeted by a pretty primitive scam.
| More than 10 years ago (after someone I love was naive and
| inexperienced, having a medium amount stolen in a sensitive and
| stressful time of this person's life). I recognised fast and
| having time and will I sarted to play along, pretending I bite
| the bait. Collecting info while acting. In parallel trying to
| connect local and international authorities to report an
| ongoing scam effort. I believe I tried 4 organizations in 3
| different countries apparently involved, I believe one was
| dedicated to online scams, also trying to warn Western Union,
| they are about to be used for scam. I even went personally to a
| police station locally to get some advice on how to assist
| catching the criminals. Since all I encountered insisted to
| report my damages, so they could start an investigation on an
| actual loss happened, I furiously gave up and decided whenever
| I will be having financial trouble I will invest my efforts in
| scamming others. No-one cares catching those in act! So the
| thugs can be incredibly bold and dumb, like the one I
| encountered, it is no effort doing better.
| miohtama wrote:
| It's national interest of China and Russia to see the West to
| fail. Why would they co-operate? They are willing to murder
| people, West and their own, so "law" enforcement means a bit
| different in international context.
| bsder wrote:
| If we were all running IPv6, we could just block this crap.
|
| But here we are in 2025 still running IPv4 with CGNAT, so we
| can't.
| dylan604 wrote:
| Because every single nation would have to sign on to it
| allowing said agency to ignore sovereignty of each nation to
| come in and do their policing.
|
| You'd also need to have every country not actively involved in
| these types of schemes yet we know some governments are
| directly benefiting from the scams/theft their citizens are
| perpetrating.
|
| You'd also need to have every country think the things you want
| to police against are wrong. Again, we know that's just not
| true.
| shoddydoordesk wrote:
| > it suddenly ballooned in size in April 2025 after its operators
| breached a TotoLink router firmware update server and infected
| approximately 100,000 devices
|
| This is scary. Everyone lauds open source projects like OpenWRT
| but... who is watching their servers?
|
| I imagine you can't run an army of security people on donations
| and a shoestring budget. Does OpenWRT use digital signing to
| mitigate this?
| sam_lowry_ wrote:
| This is exactly why OpenWRT has no unattended updates by
| default )
| shoddydoordesk wrote:
| You are dismissing the seriousness of this. Their package
| manager is widely used. One would only need to compromise
| their build servers to wreak havoc.
|
| Didn't they have a vulnerability in their firmware download
| tool like a minute ago?
|
| The difference between OpenWRT and Linux distros is the
| amount of testing and visibility. OpenWRT is loaded on to
| residential devices and forgotten about, it doesn't have
| professional sysadmins babysitting it 24/7.
|
| Remember the xz backdoor was only discovered because some
| autist at Microsoft noticed a microsecond difference in
| performance testing.
| jacobgkau wrote:
| I'm confused why you're so honed in on OpenWRT as a third-
| party open-source project here when the vulnerability you
| quoted (TotoLink) was the official firmware update server
| of a brand of devices.
|
| Is it "scary" to think about OpenWRT potentially getting
| hacked? If you get scared by theoretical possibilities in
| software, sure. Is it relevant? Not exactly. Are companies'
| official servers more secure than an open-source project's
| servers? In this case, apparently not.
| danudey wrote:
| What's scary is that OpenWRT is a project created by
| people who wanted a better solution than what was out
| there, and are therefore largely driven by a desire to
| create a good product.
|
| Meanwhile, corporations are driven entirely by profit
| motive, so as long as it's more expensive to be vigilant
| about security than it is to be lax about it they will
| never improve.
|
| Until companies which produce (and do not update)
| vulnerable equipment are penalized (e.g. charged with
| criminal negligence) for DDoS attacks using their
| hardware then the open-source projects are going to
| continue to be far more trustworthy and less vulnerable
| than corporations which mass-produce the cheapest
| hardware they can and then designating it as obsolete and
| unsupported as fast as possible to force more updates.
| whatshisface wrote:
| As always, hundreds watch the open repositories, maybe one
| watches a company's build servers, if they're lucky. :-)
| TylerE wrote:
| Hundreds watch, but how closely?
|
| Plenty of stories of fairly major projects having evil
| commits snuck in that remain for months.
| immibis wrote:
| Digital signing wouldn't defend you from a compromised build
| server.
| mbilker wrote:
| What in that act says OpenWrt would be made illegal? If
| anything, OpenWrt would roll out automated security updates
| for a supported branched release to comply with these
| regulations.
|
| Also, if you actually read it, there are exceptions for open
| source software!
| majorchord wrote:
| OP claims almost daily that some benign thing is actually
| illegal but practically never provides any useful proof
| when asked.
|
| (please prove me wrong, Alex)
| tempest_ wrote:
| I don't follow.
|
| > run an army of security people
|
| Do you think these private companies do this? They don't. They
| pay as little as humanly possible to cover their ass.
|
| Botnets comprised of compromised routers is common and
| commercial/consumer routers are a far juicer target than
| openwrt.
| nine_k wrote:
| Why, OpenWRT firmware and packages are both signed, of course.
| You can manually and independently check the image signature
| before flashing an update.
|
| The build infrastructure is, of course, a juicy target: infect
| the artifact after building but before signing, and pwn
| millions of boxes before this is detected.
|
| This is why bit-perfect reproducible builds are so important.
| OpenWRT in particular have that:
| https://openwrt.org/docs/guide-developer/security#reproducib...
| tetha wrote:
| Bit-Reproducible infrastructure could also result in some of
| the wildest build distribution architectures if you think
| about it. You could publish sources and have people register
| like in APT mirrors to provide builds, and at the end of the
| day, the build from the largest bit-equal group is published.
|
| I do see the Tor-Issue - a botnet or a well-supplied
| malicious actor could just flood it. And if you flip it - if
| you'd need agreement about the build output, it could also be
| poisoned with enough nodes to prevent releases for a critical
| security issue. I agree, I don't solve all supply chain
| issues in one comment :)
|
| But that in turn could be helped with reputation. Maybe a
| node needs to supply 6 months of perfect builds - for testing
| as well - to become eligible. Which would be defeated by
| patience, but what isn't? It'd just have to be more annoying
| to breach the distributed build infrastructure than to plant
| a malicious developer.
|
| This combination of reproducible, deterministic builds, tests
| across a number of probably-trustworthy sources is quite
| interesting, as it allows very heavy decentralization. I
| could just run an old laptop or two here to support. And then
| come compromise hundreds of these all across the world.
| smt88 wrote:
| The distribution system you're describing exists and has
| been in use for decades. You just distribute the build
| using bittorrent.
| charcircuit wrote:
| >It'd just have to be more annoying to breach the
| distributed build infrastructure than to plant a malicious
| developer.
|
| It really wouldn't. You don't even need a powerful build
| server since you can mirror whatever someone else built.
| You can also buy / hack nodes of existing trusted people.
| null_deref wrote:
| I don't mean to cast any doubt, but are those short articles the
| standard, or why was there almost no data provided?
| sva_ wrote:
| I feel like posting the traffic output of the network might not
| be a great idea because they might do these attacks on purpose to
| market their network's capability.
| kachapopopow wrote:
| it's an open secret at that point and the attacks are far
| larger than that are causing congestion world-wide from the
| time they wake up to the time they go to sleep.
| Y_Y wrote:
| _Cui bono?_
|
| There is a big (opportunity) cost to this kind of thing, How is
| this worthwhile for anyone? I assume that its's not just a
| competitor. Is it really worth <insert evil country>'s time to
| temporarily upset one of of three big cloud providers? Is there a
| ransom behind the scenes?
| kachapopopow wrote:
| nope, there's really no cost to it - they've been hitting with
| attacks double or even triple the size towards random minecraft
| hosts for months now.
| imglorp wrote:
| > it targeted a single endpoint in Australia.
|
| It would really help to understand why attack one endpoint with
| "the largest DDoS attack ever observed in the cloud". If it was
| important, it would be redundant in its CDN. Who paid for this
| attack and what did they gain?
| kachapopopow wrote:
| we were getting hit with attacks like this daily at some point
| and were forced to use cloudflare magic transit it's pretty
| random and you shouldn't read too deep into it as nearly every
| anti-ddos solution, host and isp has been hit with this botnet
| by now.
| estearum wrote:
| but why? For fun?
| kachapopopow wrote:
| yep, there's no consistency to their actions - basically
| hit a target and keep it down for as long as possible
| causing heavy business loss. to my knowledge none of the
| target servers have ever received a ransom request.
| toast0 wrote:
| I used to run servers for a very popular service. I'm 99%
| sure people DDoSed our www for lolz and also to kick the
| tires on DDoS as a service vendors. We would get DDoS on a
| pretty regular basis, for exactly 90 seconds, +/- a few
| nodes that had bad clock sync and were 2 seconds off; which
| was exactly what you get from a free trial at DDoS as a
| service. I feel like we got a ransom request like once; but
| I can't remember if it actually corresponded to an attack,
| if it did, I don't think it was consequential.
|
| Thankfully, it was almost always targetted at our www
| servers, which were not important for our service. _Very_
| occasionally, we 'd get hit on the machines that we
| actually ran our service on, but between the consistent
| DDoS on www, and our own self-inflicted DDoS from defects
| in the client code we wrote for our users, our service was
| well prepared... if the DDoS went over line rate for the
| server, our hosting provider would null route it [1], but
| otherwise, we could manage line rate of udp reflection or
| tcp syn floods and what have you. From what I could tell,
| most attackers didn't retarget to our other servers when
| one got null routed.
|
| [1] They did try a DDoS scrubbing service, but having our
| servers behind the scrubber was way worse than just null
| routing. Maybe the scrubbing could have been tuned, but as
| it was, it was better for us to just have the attacked
| servers lose connectivity to the public network.
| Razengan wrote:
| > _self-inflicted defects_
|
| is what I'll call bugs from now
| Fabricio20 wrote:
| As someone on the receiving end of these, I've yet to
| receive any explanation. Every other week we see the most
| basic of attacks against our infrastructure (http floods -
| GET / - for example), with no specific goal in mind and we
| never received any threats. I can only assume it's some
| disgruntled user or maybe a competitor, but it could also
| just be stray bullets. I don't know who used these IPs
| before us, though it's been several years we've owned them.
| Who knows.
| cookiengineer wrote:
| You are assuming that DDoS is signal. It's not, it's the noise.
|
| The idea of DDoS for hire is to bury your own tracks in as much
| network requests as possible, so that the other side is
| overwhelmed processing (or even storing) that dataset and won't
| find out what the real target was.
|
| That's literally the strategy of APT28/29.
| perfmode wrote:
| A DDoS attack is often used to distract a company's security
| team. While the security staff is scrambling to get the website
| back online, the attackers use the chaos to conduct a more
| serious, stealthy attack.
| mihaaly wrote:
| It was interesting to read that the record breaking attack
| caused no glitch whatsoever in the service MS provides. Which
| is so slow normally that I start to wonder if that is a
| strategy, having headroom for these kind of situations, no-one
| realizes slowdown when it is already slow. ;)
|
| This is just a crazy thought, tangential to what are happening
| during an attack.
| averageRoyalty wrote:
| > This attack lasted only 40 seconds but was roughly equivalent
| to streaming one million 4K videos simultaneously.
|
| Who is this for? Is there anyone reading the article that can't
| grasp what a terrabit is but can somehow conceptualise one
| million 4k videos streaming simultaneously? I don't think anyone
| sits in that venn diagram.
| haunter wrote:
| This is what I don't get
|
| >The Aisuru DDoS botnet operates as a DDoS-for-hire service with
| restricted clientele; operators have reportedly implemented
| preventive measures to avoid attacking governmental, law
| enforcement, military, and other national security properties.
| Most observed Aisuru attacks to date appear to be related to
| online gaming.
|
| https://www.netscout.com/blog/asert/asert-threat-summary-ais...
|
| So why? Like why would someone pay to take a game down? I see
| this all over reddit with different games but I just don't get
| the point. What's the benefit of taking down an online game for a
| couple of hours.
| denkmoon wrote:
| Mad salt. Imagine a fully grown man having a toddler tantrum.
| "If I can't play/win/get my way, nobody can" type mentality.
| It's also a method of coercion. Give me mod status or I'll DDOS
| your server and destroy your community.
|
| The other half comes from sever operators ddosing their
| competition. There is a lot of money to be made from paid
| cosmetics, ranks, moderator (demi-tyrant) status, etc on custom
| servers.
| manquer wrote:
| Probably it has to do with all the gambling sites associated
| with gaming not the games itself.
|
| Taking a competitor offline for a few hours is a lot of money
| in a market business I expect.
|
| there seems to be lot of weird stuff going on with gaming
| casinos the recent CoffeeZilla episode comes to mind, so
| wouldn't be surprised if not botnets are used
| iknowstuff wrote:
| They get banned for trolling, griefing, cheating, breaking
| rules etc. and want revenge. Every game operator has to deal
| with idiots like this
| AmbroseBierce wrote:
| Yeah, every single ban in every single game is 100% justified
| and game operators never make mistakes when exercising such
| punishment.
| iknowstuff wrote:
| yeah bud if the person ends up ddosing I'm 100% certain
| their ban was justified lol
| water-your-self wrote:
| At the end of the day, at least for silly private servers,
| you are always welcome to build it yourself. Theres much to
| learn in doing that.
| bstsb wrote:
| the ddos market has been somewhat centered around gaming for a
| while now, mainly to take down game server competition, or as
| an attempt to sell big players on "ddos protection" services.
|
| well, gaming and Krebs's blog:
| https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with...
| Onawa wrote:
| It depends on the game, but for those with some kind of
| marketplace or transferable currency, I'm guessing market
| manipulation is one possible reason.
|
| For other games, maybe trying to interrupt some time limited
| event or tournament. Going all the way down the rabbit hole, if
| you're not already familiar take a look at how crazy things get
| in a game like EVE: Online.
|
| Then of course there are the bored trolls and/or people who
| feel wronged by the game's developers or other players.
| zaphirplane wrote:
| Depends on How much does it cost to hire it
| hobs wrote:
| Most of the time its just blackmail/extortion - pay us or we do
| the thing.
| ddtaylor wrote:
| > So why? Like why would someone pay to take a game down? I see
| this all over reddit with different games but I just don't get
| the point. What's the benefit of taking down an online game for
| a couple of hours.
|
| Most of the time crime groups are running extortion campaigns,
| amplification campaigns, etc. For example, if a competitor can
| benefit from them being down you may be able to sell that.
| Eventually we will probably see the invention of crowd-funded
| randsomware, where everyone must submit one verification can of
| crypto to unlock the hacked game servers.
___________________________________________________________________
(page generated 2025-11-17 23:00 UTC)