Yandex has repelled the largest DDoS attack in history

disBalancer
2 min readSep 13, 2021

๐Ÿ‘‹๐Ÿป Hello everyone. In this article, we will tell you about how Yandex repelled the largest DDoS attack in history.

๐Ÿ† 20 million RPS (request per second). This record was recently set by a new botnet called Mฤ“ris (translated from Latvian as โ€œplagueโ€).

โ“ What are the features of the new botnet?

๐Ÿ”น Using pipelining in HTTP / 1.1 to organize DDoS attacks (confirmed)

๐Ÿ”น Attacks are focused on the exploitation of RPS (confirmed)

๐Ÿ”น Open port 5678/TCP (confirmed)

๐Ÿ”น SOCKS4-proxy on the infected device (not confirmed, although we know that Mikrotik devices use SOCKS4)

๐Ÿ“ข According to the companyโ€™s report, the botnet continues to grow further, while not only Yandex, but also many other companies are exposed to the threat of such a DDoS attack.

๐Ÿ“Œ Over the past two weeks, the attacks, in addition to Russia, have also targeted the United States and New Zealand. Cloudflare recently reported that they managed to repel an attack of 17 million RPS.

๐Ÿ“Œ One of the important โ€œfeaturesโ€ of this botnet is also that such a number of requests can disable even the equipment that is specially sharpened to reflect high-intensity DDoS attacks.

๐Ÿ”— Reverse L2TP tunnels are used for interaction within the network, and the number of infected devices reaches 250,000.

๐Ÿ–ฅ It is also important that IP addresses are not substituted in these cyber attacks, so they can be easily repelled by a banal blacklist for a short time.

โš™๏ธ Therefore, we can say that this attack tries to take the number of attackers, and not their quality, which will lead to the fact that the botnet will most likely cease to be a problem quite quickly, since it uses the old vulnerabilities of some routers, such as Mikrotik.

๐Ÿ’ฌ According to the Yandex report, they have already sent all the necessary information to the manufacturers, and this DDoS attack did not become a big problem for them.

โ“ What conclusion can be drawn from this?

โœ… Despite the seemingly huge resources of the Mฤ“ris botnet, which is able to send more than 200 RPS, its emphasis on quantity could not lead to significant success. This once again confirms that the disBalancer team, focusing on the quality of its cyberarmy, provides truly effective services.

--

--

disBalancer

A decentralized cybersecurity solution that performs stress testing to identify DDoS vulnerabilities and protect projects against fraudsters.