Friday, May 9, 2025
HomeDDOSLargest Layer 7 DDOS Attack Recorded By Google with 46 Million Requests...

Largest Layer 7 DDOS Attack Recorded By Google with 46 Million Requests Per Second

Published on

SIEM as a Service

Follow Us on Google News

Google has been targeted with the largest DDoS attack in history against one of its customers. An attack on one of the Google Cloud Armor customers occurred on June 1st, during which 46 million requests were sent per second to a Google Cloud Armor customer by HTTPS DDoS attacks. 

It is the most powerful Layer 7 DDoS attack that has ever been reported to date, it has surpassed the previous record by at least 76%. 

It would be equivalent to receiving all of the daily requests to Wikipedia in just a few seconds, so you can get a sense of the scale of the attack.

- Advertisement - Google News

By detecting and analyzing the traffic early in the attack cycle, Cloud Armor Adaptive Protection was able to prevent the attack from succeeding. 

A protective rule was recommended by Cloud Armor to the customer, which was delivered to the customer before the attack reached its full extent. 

With the assistance of Cloud Armor, the customer’s service was kept online, and its end users were able to continue receiving services.

Long-lasting assault

The incident happened around 09:45 Pacific Time on June 1st and is believed to be a web-based attack. In an attempt to compromise the victim’s HTTP/S load balancer, the attacker had initially been able to generate only 10,000 requests per second.

There was an increase of 100,000 RPS within eight minutes of the attack starting. Upon receiving specific data pulled from Google’s traffic analysis, Cloud Armor Protection generated an alert and a signature that kicked in based on the data.

There was a peak of 46 million requests per second two minutes later as a result of the attack. Thanks to Cloud Armor’s recommendation, the customer had already deployed the rule to enable normal operation. In the 69 minutes that followed the start of the assault, the assault came to an end.

This alert included a recommendation for a rule that can be used to block signatures with malicious intent.

In total, 5,256 source IP addresses were involved in the attack, originating from 132 countries around the world. Around 31% of the total attack traffic was generated by the top 4 countries.

There is still no information about the malware that is behind this attack. Mēris botnet appears to be the most likely provider of these services based on the geographical distribution of their use.

The use of Tor exit nodes as the delivery mechanism for the traffic is another characteristic of this attack. A significant amount of unwanted traffic can be delivered via Tor exit nodes, according to Google researchers.

Moreover, there will be continued growth in the size of the attack and evolution in tactics in the next few years. So, users should deploy robust security mechanisms to defend and mitigate such attacks.

Also Read: The Rise of Remote Workers: A Checklist for Securing Your Network – Free E-Book Download

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Cyberattackers Targeting IT Help Desks for Initial Breach

Cybercriminals are increasingly impersonating IT support personnel and trusted authorities to manipulate victims into...

New Stealthy .NET Malware Hiding Malicious Payloads Within Bitmap Resources

Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered a novel obfuscation method...

Hackers Weaponizing Facebook Ads to Deploy Multi-Stage Malware Attacks

A persistent and highly sophisticated malvertising campaign on Facebook has been uncovered by Bitdefender...

Threat Actors Target Job Seekers with Three New Unique Adversaries

Netcraft has uncovered a sharp rise in recruitment scams in 2024, driven by three...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Europol Dismantles DDoS-for-Hire Network and Arrests Four Administrators

Significant blow to cybercriminal infrastructure, Europol has coordinated an international operation resulting in the...

Dutch Services Disrupted by DDoS Attacks From Russian-Affiliated Hacktivists

Multiple Dutch organizations have experienced significant service disruptions this week due to a series...

20.5 Million DDoS Barrage Shattered Records Leading Attack Fired Off 4.8 Billion Packets

Cloudflare's latest DDoS Threat Report for the first quarter of 2025 reveals that the...