Threat Bulletin 0492: memcached amplification against a video streaming platform in Western Europe

On Tuesday 10 January 2023 at 05:38 UTC, a memcached amplification targeted a video streaming customer in Western Europe. The attack peaked at 332.0 Gbps and lasted 184 minutes. Traffic originated from 3220 autonomous systems in 58 countries, predominantly hijacked home routers.

Vector memcached amplification
Peak 332.0 Gbps
Duration 184 min
Time to mitigation 0.300 s
Attack traffic reaching origin 0.074%
Legitimate traffic challenged 0.54%

Timeline

The attack was preceded by a hacktivist channel announcing the target. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 24 points of presence.

What the customer saw

A brief increase in p99 latency of 203 ms during the first minute, then normal service.

Recommendations

  • Enable authenticated origin pulls.
  • Add a dedicated rate limit for the targeted route.
  • Keep origin IPs out of public DNS history.

10 thoughts on “Threat Bulletin 0492: memcached amplification against a video streaming platform in Western Europe”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top