Threat Bulletin 0797: memcached amplification against a healthcare portal platform in Western Europe

On Tuesday 19 March 2024 at 04:51 UTC, a memcached amplification targeted a healthcare portal customer in Western Europe. The attack peaked at 131.3 Gbps and lasted 51 minutes. Traffic originated from 2165 autonomous systems in 25 countries, predominantly compromised cloud VMs.

Vector memcached amplification
Peak 131.3 Gbps
Duration 51 min
Time to mitigation 0.445 s
Attack traffic reaching origin 0.090%
Legitimate traffic challenged 0.48%

Timeline

The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 20 points of presence.

What the customer saw

A brief increase in p99 latency of 205 ms during the first minute, then normal service.

Recommendations

  • Enable authenticated origin pulls.
  • Review allow-listed partner ranges quarterly.
  • Lower challenge thresholds on authentication endpoints during high-risk events.

5 thoughts on “Threat Bulletin 0797: memcached amplification against a healthcare portal platform in Western Europe”

  1. We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top