Cloudflare reported automatically mitigating more than 100 hyper-volumetric Layer 3/4 DDoS attacks during a month-long campaign beginning in September 2024. The attacks targeted customers in financial services, Internet services, telecommunications, and other industries, with many exceeding 2 billion packets per second or 3 terabits per second. The largest reached 3.8 Tbps, which Cloudflare described as the largest publicly disclosed DDoS attack at the time. Predominantly UDP traffic attempted to saturate network bandwidth and exhaust processing resources.
The traffic apparently originated from compromised MikroTik devices, DVRs, web servers, and ASUS home routers. Cloudflare suspected attackers had exploited a recently disclosed ASUS vulnerability rated 9.8, but did not identify its CVE. Censys separately highlighted an improper-authentication vulnerability in ASUS routers; the available information does not establish whether it was the flaw used in this campaign. Cloudflare said its global anycast network distributed attack traffic while autonomous packet-filtering systems generated real-time mitigation rules, preventing customer performance impacts. Organizations should prioritize router patching and verify that DDoS protection can withstand both bandwidth saturation and extreme packet rates.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
A separate attack against the same unnamed Cloudflare customer peaked at 2.14 billion packets per second and lasted 60 seconds. Cloudflare assessed that high-packet-rate attacks appeared to originate from compromised MikroTik devices, DVRs, and web servers operating together.
An attack against an unnamed Cloudflare customer peaked at 3.8 Tbps and lasted 65 seconds, making it the largest publicly disclosed DDoS attack at the time, according to Cloudflare. Cloudflare assessed that high-bitrate attacks in the campaign appeared to originate from compromised ASUS home routers.
A month-long campaign beginning in early September targeted Cloudflare customers in financial services, Internet services, telecommunications, and other industries. Cloudflare autonomously mitigated more than 100 Layer 3/4 attacks, many exceeding 2 billion packets per second or 3 Tbps; the source did not specify the year.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.