Threat Bulletin 1026: CLDAP reflection against a gaming community platform in the Nordics

On Sunday 2 February 2025 at 11:23 UTC, a CLDAP reflection targeted a gaming community customer in the Nordics. The attack peaked at 106.7 Gbps and lasted 146 minutes. Traffic originated from 3332 autonomous systems in 102 countries, predominantly misconfigured open reflectors.

Vector CLDAP reflection
Peak 106.7 Gbps
Duration 146 min
Time to mitigation 0.775 s
Attack traffic reaching origin 0.082%
Legitimate traffic challenged 0.60%

Timeline

The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 22 points of presence.

What the customer saw

A brief increase in p99 latency of 161 ms during the first minute, then normal service.

Recommendations

  • Enable authenticated origin pulls.
  • Review allow-listed partner ranges quarterly.
  • Lower challenge thresholds on authentication endpoints during high-risk events.

3 thoughts on “Threat Bulletin 1026: CLDAP reflection against a gaming community platform in the Nordics”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top