Threat Bulletin 0212: UDP reflection (DNS) against a retail banking platform in Iberia

On Friday 17 December 2021 at 02:52 UTC, a UDP reflection (DNS) targeted a retail banking customer in Iberia. The attack peaked at 37.2 Gbps and lasted 157 minutes. Traffic originated from 3519 autonomous systems in 103 countries, predominantly a headless-browser farm.

Vector UDP reflection (DNS)
Peak 37.2 Gbps
Duration 157 min
Time to mitigation 0.949 s
Attack traffic reaching origin 0.012%
Legitimate traffic challenged 0.04%

Timeline

The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 35 points of presence.

What the customer saw

No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.

Recommendations

  • Enable log streaming to your SIEM for faster correlation.
  • Lower challenge thresholds on authentication endpoints during high-risk events.
  • Review allow-listed partner ranges quarterly.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top