Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

241–250 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#241
post #236
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

> What's the benefit of taking down an online game for a couple of hours. Competitive MMO. Imagine some event is setup to start at some time and your guild or alliance knows they're gonna lose it and the resource it gives: DDOS the server so it's down during the event so it does not run. Enjoy the fact you kept the asset linked to said event and sell the resources you get for real money. If you've never played those…

EVE Online had to put their foot down when people were talking about what could easily be considered terrorism.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#242
post #104

Earlier quoted context omitted.

the ddos market has been somewhat centered around gaming for a while now, mainly to take down game server competition, or as an attempt to sell big players on "ddos protection" services. well, gaming and Krebs's blog: https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with...

Yep, Minecraft servers get DDoSed so often that Cloudflare actually offers turnkey protection for them specifically. https://www.cloudflare.com/en-gb/application-services/produc...

$1 per gig overage?

I'd be using someone else's credit card for that...

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#243
post #148

> Aisuru is a Turbo Mirai-class IoT botnet IoT botnet. Just read that again, we're literally inventing problems where none needs to exist. IoT adds basically null or negative value, except to nerds who like to think they're smarter than other people by consuming the latest e-slop. Its all so tiresome.

Most "IoT botnet" devices are Wi-Fi routers and IP cameras. Which are the two classes of IoT devices that provide undisputed value.

Maybe, just maybe, people aren't as stupid as you think they are?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#244

> This attack lasted only 40 seconds What's the point of this? Are they continuously running DDoS somewhere and 40 second is what the buyer paid for?

"Look at how big of a botnet we have! Imagine all of that, but on the target YOU want to go down!"

It's how you do marketing, basically.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#245
post #120

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

If we were all running IPv6, we could just block this crap. But here we are in 2025 still running IPv4 with CGNAT, so we can't.

Not sure how this would work, if you blocked those IPv6, the mostly innocent companies and people that are now blocked will be in short order getting a new IPv6 assigned by the ISP after a support call.

I was under the impression that these botnets still rely on vulnerable computers, which have a human that will be calling support asking for the issue to be resolved.

Then it needs an ISP to figure out the issue and ask the client to sort out their compromised computer, but unlikely the ISP will stop a paying customer from internet access especially if it's not clear why their original assigned IPv6 is blocked.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#246
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

Mad salt. Imagine a fully grown man having a toddler tantrum. "If I can't play/win/get my way, nobody can" type mentality. It's also a method of coercion. Give me mod status or I'll DDOS your server and destroy your community. The other half comes from sever operators ddosing their competition. There is a lot of money to be made from paid cosmetics, ranks, moderator (demi-tyrant) status, etc on custom servers.

On my childhood I had a colleague were when him lose a match against me or my brother, him got mad and fire the joystick to the ground.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#248
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

Speculation online as to the why in this case, it's pure advertisement of their capabilities.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#249
post #201
post #184

Earlier quoted context omitted.

Torrent files are hashed, so it's exactly the same risk profile as the comment I was referring to. But generally hashing algorithms are collision-proof enough that what you're describing is basically impossible (requiring many years of compute time).

IIRC BitTorrent still uses SHA-1, which is becoming more problematic.

BitTorrent v2 uses SHA-256, but in any case SHA-1 is still second-preimage resistant. And the BitTorrent piece hashes are included in the .torrent file, so you would need to find a double collision.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#250

Man, if you had that many nodes can you guys imagine how much cool tech you could build with that? Like you could literally rival Tor with one command. Or build a decentralized archive system. Yet, the only thing these nodes will end up doing is being used to prop up some losers ego. Literally what a waste. If you're going to commit crime at least do something cool.

You could easily get better performance with a pair of well-optimized high-density cabinets, much more reliable and not even that expensive to operate legitimately.
Post reply on HN