{"id":4799,"date":"2025-06-21T10:04:19","date_gmt":"2025-06-21T10:04:19","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/21\/record-breaking-7-3-tbps-ddos-attack-blasting-37-4-terabytes-in-just-45-seconds\/"},"modified":"2025-06-21T10:04:19","modified_gmt":"2025-06-21T10:04:19","slug":"record-breaking-7-3-tbps-ddos-attack-blasting-37-4-terabytes-in-just-45-seconds","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/21\/record-breaking-7-3-tbps-ddos-attack-blasting-37-4-terabytes-in-just-45-seconds\/","title":{"rendered":"Record Breaking 7.3 Tbps DDoS Attack Blasting 37.4 Terabytes in Just 45 Seconds"},"content":{"rendered":"<p>    Record Breaking 7.3 Tbps DDoS Attack Blasting 37.4 Terabytes in Just 45 Seconds<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The largest distributed <a href=\"https:\/\/cybersecuritynews.com\/ddos-attacks-use-iot-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial-of-service (DDoS)<\/a> attack ever documented was successfully stopped by Cloudflare in mid-May 2025, with attackers unleashing a devastating 7.3 terabits per second (Tbps) attack that delivered 37.4 terabytes of malicious traffic in just 45 seconds.\u00a0<\/p>\n<pre class=\"wp-block-code\" style=\"font-size:14px\"><code><strong><mark style=\"background-color:rgba(0, 0, 0, 0);color:#0733a2\" class=\"has-inline-color\">Summary<\/mark><\/strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">\n<\/mark>1. Cloudflare blocked a record 7.3 Tbps DDoS attack in mid-May 2025, delivering 37.4 TB of malicious traffic in 45 seconds.\n2. Targeting a hosting provider using Cloudflare's Magic Transit, the attack surpassed the previous record by 12%.\u00a0\n3. It used sophisticated multi-vector techniques, mainly UDP floods (99.996%), with additional amplification attacks.\n4. Zero-touch architecture with anycast routing and gossip protocol quickly contained the attack, showcasing unparalleled scalability.<\/code><\/pre>\n<p>This unprecedented cyberattack targeted a hosting provider customer using Cloudflare\u2019s Magic Transit service and represents a 12% increase over the previous record, demonstrating the escalating scale and sophistication of modern DDoS campaigns.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeC-LbpcpvpwD8wXL_v4GS_mOB5AZ4gt8jyqTk0KJizuTdRRjdRo7_Z2Pf2pSrR1z3XAjitXwd3U6NVK7qEuy-9eJxGVPIvL3lEIqpSpCDph4cNOdpUXenr_CnX9m2eGlf2XOKw5w?key=XfesNA7blpVr9eID5yMbFg\" alt=\"\"><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Multi-vector DDoS Attack\u00a0<\/strong><\/h2>\n<p>The massive attack employed a multi-vector approach, with 99.996% of the attack traffic consisting of <a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-zyxel-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">UDP floods<\/a> targeting an average of 21,925 destination ports on a single IP address, peaking at 34,517 ports per second.\u00a0<\/p>\n<p>The remaining 0.004% utilized sophisticated reflection and amplification techniques, including Quote of the Day (QOTD) protocol exploitation on UDP port 17, Echo protocol attacks on UDP\/TCP port 7, and Network Time Protocol (NTP) amplification using the monlist command.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcVPAweOyV8VZeOgh2HuO9QPbQqh7AXBtkawDEfEP5dV6VRPJCrzx5Vsn45e9Kcat3bNnSoB3UY3wDJqpnQGzi4eiocIK38twkGFLnejTsaMZyU6pL1zotC-MKpLTHA3l9qNDRd?key=XfesNA7blpVr9eID5yMbFg\" alt=\"\"><\/figure>\n<\/div>\n<p>Additional attack vectors included Mirai botnet UDP floods, Portmap service exploitation on UDP port 111, and Routing Information Protocol version 1 (RIPv1) attacks on UDP port 520.<\/p>\n<p>The attack demonstrated a remarkable geographical distribution, originating from 122,145 unique source IP addresses spanning 5,433 Autonomous Systems (AS) across 161 countries.\u00a0<\/p>\n<p>Brazil and Vietnam emerged as the primary attack sources, each contributing approximately 25% of the total traffic volume, while Taiwan, China, Indonesia, Ukraine, Ecuador, Thailand, the United States, and Saudi Arabia collectively accounted for another third of the malicious traffic.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcWB43OGcMOCvjugNt5uLwIqKhJnwW1S-xeaSpKgJHZTG9rIfjSpiD2F1EFjub2dPWANTBkLDm7XPrnoasZyR0U8L2iw2T2Os7ZJNsrADWp9O4zugQ_sEgraLZWdgugXoJ9ssLeLQ?key=XfesNA7blpVr9eID5yMbFg\" alt=\"\"><\/figure>\n<\/div>\n<p>Telefonica Brazil (AS27699) led the participating networks with 10.5% of attack traffic, followed closely by Viettel Group (AS7552), contributing 9.8%.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Autonomous Detection and Mitigation Technology<\/strong><\/h2>\n<p>Cloudflare\u2019s defense systems leverage advanced packet sampling technology using eXpress Data Path (XDP) and extended Berkeley Packet Filter (eBPF) programs within the Linux kernel to analyze traffic patterns in real-time, according to the <a href=\"https:\/\/blog.cloudflare.com\/defending-the-internet-how-cloudflare-blocked-a-monumental-7-3-tbps-ddos\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a>.<\/p>\n<p>The company\u2019s proprietary heuristic engine, dubbed \u201cdosd\u201d (denial of service daemon), automatically generated multiple fingerprint permutations to identify attack patterns while minimizing impact on legitimate traffic.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXc6rLLTN2pzFR9dcOaV5gM8Y73bQ7_cnq4xfhvNf1gy2aD-dboV3nis_F8pNE_pzq_-CMZtoI2d90Z017BSiki1Z8lX-YpfumK8au12SXEICSkKo4douh3PVw3f6D5BaFGYXGTOgg?key=XfesNA7blpVr9eID5yMbFg\" alt=\"\"><\/figure>\n<\/div>\n<p>The attack was detected and mitigated across 477 data centers in 293 global locations using anycast routing, which distributed the attack traffic across Cloudflare\u2019s network infrastructure.\u00a0<\/p>\n<p>Each data center maintained localized <a href=\"https:\/\/cybersecuritynews.com\/threat-intelligence-in-cybersecurity\/\" target=\"_blank\" rel=\"noreferrer noopener\">threat intelligence<\/a> caches updated through a gossip protocol, ensuring sub-second propagation of emerging attack signatures across the entire network.\u00a0<\/p>\n<p>This integrated autonomous framework achieved zero-touch mitigation for the 7.3 Tbps attack, fully containing the incident within its 45-second duration without triggering incident response protocols.<\/p>\n<p>The entire mitigation process occurred autonomously without human intervention, alerts, or service incidents, showcasing the effectiveness of modern cloud-based DDoS protection systems in defending against increasingly sophisticated cyber threats.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Are you from SOC\/DFIR Teams! - Interact with malware in the sandbox and find related IOCs. -\u00a0<a href=\"https:\/\/any.run\/demo\/?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=threat_hunting_tips&amp;utm_term=190625&amp;utm_content=linktodemo\" target=\"_blank\" rel=\"noreferrer noopener\">Request 14-day free trial<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/record-breaking-ddos-attack-2\/\">Record Breaking 7.3 Tbps DDoS Attack Blasting 37.4 Terabytes in Just 45 Seconds<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/record-breaking-ddos-attack-2\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Record Breaking 7.3 Tbps DDoS Attack Blasting 37.4 Terabytes in Just 45 Seconds The largest distributed denial-of-service (DDoS) attack ever documented was successfully stopped by Cloudflare in mid-May 2025, with attackers unleashing a devastating 7.3 terabits per second (Tbps) attack that delivered 37.4 terabytes of malicious traffic in just 45 seconds.\u00a0 Summary 1. Cloudflare blocked [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[677,129,63,326,131],"tags":[130],"class_list":["post-4799","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-article","category-cyber-security","category-cyber-security-news","category-ddos","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4799"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4799"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4799\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4799"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}