Saturday, May 24, 2025
HomeDDOSGoogle, Pornhub and Amazon hit with Memcached-based DDoS Attack - KillSwitch &...

Google, Pornhub and Amazon hit with Memcached-based DDoS Attack – KillSwitch & PoC

Published on

SIEM as a Service

Follow Us on Google News

Memcached DDOS attacks raise from nowhere and made some record-breaking DDoS attacks. GitHub Hit With a massive 1.35 Tbps DDoS Attack and within 5 days an American firm hit with a records breaking 1.7 Tbps DDoS Attack.

Two Proof of concepts for the Memcache DDOS attacks has been published online. The written in C language and the scripts utilize a list of 17,000 vulnerable Memcached servers to launch a DDoS attack.

The second one built in python and it inherits Shodan API to find the list of vulnerable Memcached servers.

- Advertisement - Google News

Memcached DDOS attacks

The PoC published online made the attack even worst, it allows even a script kiddle to launch a high volume Memcached DDoS Attack.

But here is the good news “Security researchers from Corero Network Security identified a kill switch” which sends a command back to attacker server to suppress the DDoS exploitation. Based on this finding a DDOS Mitigation tool dubbed Memfixed released.

Josh Lospinoso published a memcachedump tool for dumping the cache contents of the exposed Memcached servers, and according to the dump reports the number of exposed vulnerable servers is decreasing slowly.

Targets of Memcached DDOS attacks

The attack was primarily concentrated in United States, China (including Hong Kong, China), South Korea, Brazil, France, Germany, the United Kingdom, Canada, and the Netherlands.

According to netlab analysis via ddosmon within 7 days 10k attack events and 7131 unique victim IP addresses were logged.

The Memcached DDOS attacks having some interesting targets

The regular big players such as qq,360, Google, Amazon.etc
The game industry such as rockstargames.com, minecraft.net, playstation.net
The porn sites such as pornhub.com, homepornbay.com
The security industry such Avast.com, kaspersky-labs.com, 360.cn
The political related websites such as nra.org, nrafoundation.org, nracarryguard.com, epochtimes.com
And the guy who always gets to see the newest DDoS attack: krebsonsecurity.com 🙂

Memcached DDOS attacksCloudflare named it as an amplification attack A carefully crafted technique allows an attacker with limited IP spoofing capacity (such as 1Gbps) to launch very large attacks (reaching 100s Gbps) “amplifying” the attacker’s bandwidth.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets

A new project has exposed a critical attack vector that exploits protocol vulnerabilities to...

Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000

A threat actor known as #LongNight has reportedly put up for sale remote code...

Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability

Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager...

Hackers Target macOS Users with Fake Ledger Apps to Deploy Malware

Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Leverage DDoS Attacks as Smokescreens for Data Theft

Distributed Denial of Service (DDoS) attacks, once seen as crude tools for disruption wielded...

Europol Dismantles DDoS-for-Hire Network and Arrests Four Administrators

Significant blow to cybercriminal infrastructure, Europol has coordinated an international operation resulting in the...

Dutch Services Disrupted by DDoS Attacks From Russian-Affiliated Hacktivists

Multiple Dutch organizations have experienced significant service disruptions this week due to a series...