On Tuesday 19 March 2024 at 04:51 UTC, a memcached amplification targeted a healthcare portal customer in Western Europe. The attack peaked at 131.3 Gbps and lasted 51 minutes. Traffic originated from 2165 autonomous systems in 25 countries, predominantly compromised cloud VMs.
| Vector | memcached amplification |
| Peak | 131.3 Gbps |
| Duration | 51 min |
| Time to mitigation | 0.445 s |
| Attack traffic reaching origin | 0.090% |
| Legitimate traffic challenged | 0.48% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 20 points of presence.
What the customer saw
A brief increase in p99 latency of 205 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Review allow-listed partner ranges quarterly.
- Lower challenge thresholds on authentication endpoints during high-risk events.
Thanks — sharing this with our on-call team.
Solid runbook advice. The DNS-at-2am point hit home.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
Thanks — sharing this with our on-call team.
We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.