Threat Bulletin 1162: CLDAP reflection against a gaming community platform in the Nordics

On Friday 8 August 2025 at 21:23 UTC, a CLDAP reflection targeted a gaming community customer in the Nordics. The attack peaked at 310.1 Gbps and lasted 176 minutes. Traffic originated from 2458 autonomous systems in 40 countries, predominantly a headless-browser farm.

Vector CLDAP reflection
Peak 310.1 Gbps
Duration 176 min
Time to mitigation 0.277 s
Attack traffic reaching origin 0.070%
Legitimate traffic challenged 0.21%

Timeline

The attack was preceded by a publicly announced sales event. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 13 points of presence.

What the customer saw

Checkout conversion was unchanged compared with the same hour of the previous week.

Recommendations

  • Review allow-listed partner ranges quarterly.
  • Add a dedicated rate limit for the targeted route.
  • Enable authenticated origin pulls.

2 thoughts on “Threat Bulletin 1162: CLDAP reflection against a gaming community platform in the Nordics”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top