Categories: DDOS

Google, Pornhub and Amazon hit with Memcached-based DDoS Attack – KillSwitch & PoC

Memcached DDOS attacks raise from nowhere and made some record-breaking DDoS attacks. GitHub Hit With a massive 1.35 Tbps DDoS Attack and within 5 days an American firm hit with a records breaking 1.7 Tbps DDoS Attack.

Two Proof of concepts for the Memcache DDOS attacks has been published online. The written in C language and the scripts utilize a list of 17,000 vulnerable Memcached servers to launch a DDoS attack.

The second one built in python and it inherits Shodan API to find the list of vulnerable Memcached servers.

The PoC published online made the attack even worst, it allows even a script kiddle to launch a high volume Memcached DDoS Attack.

But here is the good news “Security researchers from Corero Network Security identified a kill switch” which sends a command back to attacker server to suppress the DDoS exploitation. Based on this finding a DDOS Mitigation tool dubbed Memfixed released.

Josh Lospinoso published a memcachedump tool for dumping the cache contents of the exposed Memcached servers, and according to the dump reports the number of exposed vulnerable servers is decreasing slowly.

Targets of Memcached DDOS attacks

The attack was primarily concentrated in United States, China (including Hong Kong, China), South Korea, Brazil, France, Germany, the United Kingdom, Canada, and the Netherlands.

According to netlab analysis via ddosmon within 7 days 10k attack events and 7131 unique victim IP addresses were logged.

The Memcached DDOS attacks having some interesting targets

The regular big players such as qq,360, Google, Amazon.etc
The game industry such as rockstargames.com, minecraft.net, playstation.net
The porn sites such as pornhub.com, homepornbay.com
The security industry such Avast.com, kaspersky-labs.com, 360.cn
The political related websites such as nra.org, nrafoundation.org, nracarryguard.com, epochtimes.com
And the guy who always gets to see the newest DDoS attack: krebsonsecurity.com 🙂

Cloudflare named it as an amplification attack A carefully crafted technique allows an attacker with limited IP spoofing capacity (such as 1Gbps) to launch very large attacks (reaching 100s Gbps) “amplifying” the attacker’s bandwidth.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently detailed…

9 hours ago

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria Stealer,"…

9 hours ago

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton Pass,…

9 hours ago

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly sophisticated…

9 hours ago

Hackers Impersonate Top Tax Firm with 40,000 Phishing Messages to Steal Credentials

Proofpoint researchers have identified a marked increase in phishing campaigns and malicious domain registrations designed…

9 hours ago

Cybercriminals Exploit Public-Facing IIS, Apache, and SQL Servers to Breach Gov & Telecom Systems

A recent investigation by Unit 42 of Palo Alto Networks has uncovered a sophisticated, state-sponsored…

9 hours ago