Microsoft reports dismantling largest cloud DDoS attack ever

Source Cryptopolitan

The denial-of-service (DDoS) attack detected on Microsoft’s cloud on October 24 has been taken down, the Windows operating system developer said on Monday.

According to Microsoft’s blog, the DDoS assault targeted a single endpoint in Australia and reached 15.72 terabits per second (Tbps) and nearly 3.64 billion packets per second (pps).

The attack was traced to a TurboMirai-class Internet of Things (IoT) botnet known as AISURU, which security firm Krebson discovered had compromised US internet service providers AT&T, Verizon and Comcast for almost a year. 

Microsoft did not reveal the identity of the target, but confirmed its automated defenses neutralized the attack before any significant disruption occurred.

AISURU could have executed record-breaking attacks

Per the analysis published by Microsoft, the assault relied on extremely high-rate UDP floods on a specific public IP address. “The attack involved extremely high-rate UDP floods targeting a specific public IP address, launched from over 500,000 source IPs across various regions,” Senior Product Marketing Manager of Azure Security Sean Whalen explained.

Azure’s analysts wrote that minimal source spoofing and randomized source ports were used to simplify traceback and enable ISPs to enforce mitigation measures effectively.

AISURU exploits compromised home routers, cameras, and DVR systems within residential ISPs in the United States and other countries. QiAnXin XLab estimates the botnet commands nearly 300,000 infected devices. 

“Aisuru’s owners are continuously scanning the Internet for these vulnerable devices and enslaving them for use in distributed denial-of-service (DDoS) attacks that can overwhelm targeted servers with crippling amounts of junk traffic,” KrebsOnSecurity researchers noted.

American AIOps and technology company Netscout also found AISURU operating with a restricted clientele to avoid government, military, and law enforcement. The majority of observed attacks are linked to online gaming platforms, where high-volume traffic can cause collateral disruption to other networks.

“The outbound and cross-bound DDoS attacks can be just as disruptive as the inbound stuff. We’re now in a situation where ISPs are routinely seeing terabit-per-second plus outbound attacks from their networks that can cause operational problems,” Netscout engineer Roland Dobbins surmised.

Azure’s Whalen also mentioned that the botnet facilitates credential stuffing, AI-driven web scraping, spamming, phishing, and operates a residential proxy service, with attacks exceeding 20 Tbps.

AISURU botnet damages in 2025 so far

In May, cybersecurity blog KrebsOnSecurity reported a near-record 6.35 Tbps attack that was countered by Google’s Project Shield. AISURU then crossed the record with an 11 Tbps assault within the next months, and by late September, attacks had topped 22 Tbps. 

The botnet sent 29.6 Tbps of junk data to a dedicated server measuring extreme DDoS traffic, according to an October 6 report by security journalist Brian Krebs. 

Steven Ferguson, principal security engineer at Global Secure Layer (GSL) in Brisbane, said TCPShield, a DDoS protection service supporting over 50,000 Minecraft servers, was hit with more than 15 Tbps of junk data on October 8. 

“This was causing serious congestion on their Miami external ports for several weeks, shown publicly via their weather map,” Ferguson said.

The attack caused significant congestion on upstream provider OVH’s Miami ports, leaving the company with no choice but to terminate service for TCPShield. However, he revealed the network is now fully protected by GSL security services, a subscription that smaller ISPs may not have the budget to pay for.

Although the DDoS exploits target online gaming networks mostly, the volume of malicious traffic affects unrelated services and connectivity in the surrounding area. Most organizations do not have the resources to withstand such attacks because they lack specialized mitigation tools that could protect them from exposure and damage.

Microsoft’s disclosure comes on the heels of Netscout’s reporting on Eleven11, also known as RapperBot, another TurboMirai-class IoT botnet. Between late February and August, Eleven11 is estimated to have launched approximately 3,600 DDoS attacks.

Some of Eleven11’s command-and-control (C2) servers were registered under the “.libre” top-level domain (TLD), part of OpenNIC, an alternative DNS root independent of ICANN. Malware analysis also revealed that the botnet used ICANN generic top-level domains (.live and .info), with C2 server IPs encrypted in the records. 

Netscout cited samples from 2024 showing Eleven11’s source code had matured to dynamically reconfigure C2 infrastructure using domain names rather than hardcoded IPs. 

Want your project in front of crypto’s top minds? Feature it in our next industry report, where data meets impact.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Bitcoin Breaks Below $92,000 as Traders Debate Whether 4-Year Cycle Pattern Is Driving Sell-OffBitcoin (BTC-USD) extended its losses on Monday, slipping below the $92,000 mark and pushing its decline from October’s all-time high to more than 26%. The ongoing downturn has reignited a key debate among traders: Is this a short-term correction, or the start of a prolonged bear market driven by Bitcoin’s historical four-year cycle?
Author  Mitrade
10 hours ago
Bitcoin (BTC-USD) extended its losses on Monday, slipping below the $92,000 mark and pushing its decline from October’s all-time high to more than 26%. The ongoing downturn has reignited a key debate among traders: Is this a short-term correction, or the start of a prolonged bear market driven by Bitcoin’s historical four-year cycle?
placeholder
Yen Plummets to Nine-Month Low as Fed Rate Cut Bets FadeThe yen hits a nine-month low against the dollar, driven by declining expectations for a Federal Reserve rate cut. Japanese officials express concern over the rapid currency depreciation and economic impact.
Author  Mitrade
15 hours ago
The yen hits a nine-month low against the dollar, driven by declining expectations for a Federal Reserve rate cut. Japanese officials express concern over the rapid currency depreciation and economic impact.
placeholder
Nvidia Earnings in Focus as Asian Markets Cautiously Await Key Economic DataAsian stock markets are on edge as investors eye Nvidia’s upcoming earnings report amid speculation surrounding interest rates and the broader implications for the AI stock rally and U.S. economic indicators.
Author  Mitrade
Yesterday 06: 02
Asian stock markets are on edge as investors eye Nvidia’s upcoming earnings report amid speculation surrounding interest rates and the broader implications for the AI stock rally and U.S. economic indicators.
placeholder
Bitcoin Plunges Below $100,000: Market Panic Intensifies as Analysts Warn of Bear Market AheadBitcoin's price has plummeted beneath the $100,000 mark, reflecting increased caution in the market toward risk assets. With large investment funds and corporate treasuries pulling back, signs of a bear market are becoming apparent, leading analysts to note a significant decline in market sentiment. Concurrently, demand for protective options in the derivatives market has surged, indicating heightened investor fears about future price movements. Despite Bitcoin maintaining some gains since the beginning of the year, recent trends raise concerns, necessitating close attention to upcoming critical support levels.
Author  Mitrade
Nov 14, Fri
Bitcoin's price has plummeted beneath the $100,000 mark, reflecting increased caution in the market toward risk assets. With large investment funds and corporate treasuries pulling back, signs of a bear market are becoming apparent, leading analysts to note a significant decline in market sentiment. Concurrently, demand for protective options in the derivatives market has surged, indicating heightened investor fears about future price movements. Despite Bitcoin maintaining some gains since the beginning of the year, recent trends raise concerns, necessitating close attention to upcoming critical support levels.
placeholder
Yen Slips as Japan Embraces Low Rates; Aussie Rises on Job GainsThe yen weakens significantly against the euro and dollar after Japan's Prime Minister supports sustained low interest rates. In contrast, the Australian dollar gains strength following better-than-expected employment figures, reducing the likelihood of near-term rate cuts.
Author  Mitrade
Nov 13, Thu
The yen weakens significantly against the euro and dollar after Japan's Prime Minister supports sustained low interest rates. In contrast, the Australian dollar gains strength following better-than-expected employment figures, reducing the likelihood of near-term rate cuts.
goTop
quote