Hacking

Cloudflare mitigated 89 hyper-volumetric HTTP distributed DDoS attacks exceeding 100 million rps

Cloudflare mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks exploiting the flaw HTTP/2 Rapid Reset.

Cloudflare DDoS threat report of 2023 states that the company has mitigated thousands of hyper-volumetric HTTP distributed denial-of-service attacks.

89 of the attacks mitigated by the company exceeded 100 million requests per second (rps), the largest attack peaked at 201 million rps, which is three times higher than the previous largest attack on record (71M rps). These attacks exploited the HTTP/2 Rapid Reset vulnerability (CVE-2023-44487).

“The campaign contributed to an overall increase of 65% in HTTP DDoS attack traffic in Q3 compared to the previous quarter. Similarly, L3/4 DDoS attacks also increased by 14% alongside numerous attacks in the terabit-per-second range — the largest peaked at 2.6 Tbps.” reads the report published by the company.

The frequency of HTTP DDoS attacks in Q3 rose by 15% compared to Q2. The researchers reported that, in the current quarter, this trend intensified significantly. In Q2, the volume of attacks increased 65% compared to the previous quarter, the researchers reported a total of 8.9 trillion HTTP DDoS requests automatically detected and mitigated by Cloudflare infrastructure.

The botnets used to launch the attacks leverage cloud computing platforms and exploit HTTP/2, they were able to generate up to x5,000 more force per botnet node. This amplification factor allows a small botnet ranging 5-20 thousand nodes to launch hyper-volumetric DDoS attacks.

According to the report, the analysis of the two-month-long DDoS campaign revealed that Cloudflare infrastructure was the main target of the attacks. 19% of all attacks targeted Cloudflare websites and infrastructure, 18% targeted Gaming companies, and 10% targeted well-known VoIP providers.

The top sources of the attacks are the U.S., China, Brazil, Germany, and Indonesia.

The U.S., Singapore, China, Vietnam, and Canada are the main targets of HTTP DDoS attacks.

The top attacked industries by HTTP DDoS attacks are the Gaming and Gambling industry and Cryptocurrency industry.

“Aside from the most common attack vectors, we also saw significant increases in lesser known attack vectors. These tend to be very volatile as threat actors try to “reduce, reuse and recycle” older attack vectors. These tend to be UDP-based protocols that can be exploited to launch amplification and reflection DDoS attacks.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Cloudflare)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

A cyber attack hit Petróleos de Venezuela (PDVSA) disrupting export operations

A cyber attack hit Petróleos de Venezuela (PDVSA), Venezuela's state-owned oil company, over the weekend,…

3 hours ago

Hackers are exploiting critical Fortinet flaws days after patch release

Threat actors are exploiting two critical Fortinet flaws, tracked as CVE-2025-59718 and CVE-2025-59719, days after…

11 hours ago

Pornhub targeted in extortion attempt following Mixpanel breach exposing user activity<gwmw style="display:none;"></gwmw>

Hackers tied to ShinyHunters extort PornHub after stealing search and viewing history of Premium users…

18 hours ago

French Interior Minister says hackers breached its email servers

The French interior minister confirmed that a cyberattack breached the Interior Ministry, compromising its email…

21 hours ago

U.S. CISA adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple and Gladinet CentreStack and Triofox flaws…

1 day ago

Atlassian fixed maximum severity flaw CVE-2025-66516 in Apache Tika

Atlassian released security updates to address dozens of flaws, including multiple critical-severity vulnerabilities. Atlassian addressed…

1 day ago

This website uses cookies.