Threat Bulletin 0262: ACK flood against a online casino platform in Latin America

On Thursday 24 February 2022 at 06:25 UTC, a ACK flood targeted a online casino customer in Latin America. The attack peaked at 310.1 Gbps and lasted 143 minutes. Traffic originated from 720 autonomous systems in 31 countries, predominantly a Mirai-derived IoT botnet.

Vector ACK flood
Peak 310.1 Gbps
Duration 143 min
Time to mitigation 0.581 s
Attack traffic reaching origin 0.012%
Legitimate traffic challenged 0.08%

Timeline

The attack was preceded by a publicly announced sales event. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 15 points of presence.

What the customer saw

A brief increase in p99 latency of 180 ms during the first minute, then normal service.

Recommendations

  • Enable log streaming to your SIEM for faster correlation.
  • Lower challenge thresholds on authentication endpoints during high-risk events.
  • Keep origin IPs out of public DNS history.

4 thoughts on “Threat Bulletin 0262: ACK flood against a online casino platform in Latin America”

  1. How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top