Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

141–150 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#141
post #73

Earlier quoted context omitted.

Yep. Manufacturers / distributors should be held responsible. Aligning the incentives is half the battle.

Yes, need to protect Azure from those evil manufacturers.

Azure AWS and cloudflare will survive, then everything else will pay them for protection; when all of the internet is captive, they will lobby for regulation to reduce the costs.

It would be better to get the regulation set up before stronger gatekeepers are created

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#142
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

I'm surprised no one has mentioned duping. Selling items and currency for real world money is big bucks and IME, server crashes reliably enable duping exploits.

Not saying that's the case in this particular incident though.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#143
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

What is even more interesting why attack Azure? It's not possible to extort anything from Microsoft, so what's the rationale?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#145
post #31

I feel like posting the traffic output of the network might not be a great idea because they might do these attacks on purpose to market their network's capability.

Why wouldn't microsoft advertise this though? If they had the ability to take the attack and others might not, then it'll result in more customers for them.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#146
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

I've always imagined somebody will get pissed-off at me one day for banning them for bad behavior, or because I said something wrong online.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#148
> Aisuru is a Turbo Mirai-class IoT botnet

IoT botnet. Just read that again, we're literally inventing problems where none needs to exist.

IoT adds basically null or negative value, except to nerds who like to think they're smarter than other people by consuming the latest e-slop.

Its all so tiresome.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#149

> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?

I don't follow. > run an army of security people Do you think these private companies do this? They don't. They pay as little as humanly possible to cover their ass. Botnets comprised of compromised routers is common and commercial/consumer routers are a far juicer target than openwrt.

> They pay as little as humanly possible to cover their ass.

They probably spend more on the team who ends up writing the "We take your security very seriously" breach notification message than they do on "security people". At least until then get forced into brand-name external Cyber Security Consultants to "investigate" their breach and work out who they can plausibly blame it on that's not part of the C suite.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#150
post #143
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

What is even more interesting why attack Azure? It's not possible to extort anything from Microsoft, so what's the rationale?

Misdirection. If I knock _you_ offline, its not going to be that difficult for you to put together a probable suspects list with me on it.

If it's going to cost me about the same in terms of resources to target you and a bunch of other people colocated with you, it's a bit less obvious who launched it and why.

Post reply on HN