Connect with us

NEWS

The 2.45 Billion Request DDoS That Rate Limits Missed

A mid-April DDoS threw 2.45 billion requests from 1.2 million IPs, sitting far below 2025 HTTP peaks while still skipping per-IP rate limits.

Published

on

A mid-April 2026 DDoS threw 2.45 billion requests at a large user-generated content platform in five hours, and per-IP rate limits never fired. DataDome, the bot-protection firm on the account, said the flood came from 1.2 million IP addresses and peaked at 205,344 requests per second.

That peak sits about 1,000 times below the HTTP floods Cloudflare mitigated on December 19, 2025. The April crew aimed at a cheaper target: the per-IP counters still baked into most WAF defaults.

The Peak Sat 1,000 Times Below Last Winter’s Floods

Jerome Segura, DataDome’s VP of Threat Research, published the case on May 5, 2026. His team counted a sustained average of roughly 136,000 requests per second across the five-hour window, which is 18,000 seconds, and that average lines up with 136,111 requests per second if you divide 2.45 billion by that span.

Four months earlier, Cloudflare’s Cloudforce One logged HTTP DDoS peaks of 205 million requests per second during the Aisuru-Kimwolf “Night Before Christmas” campaign. At that rate, 2.45 billion requests would land in about 12 seconds. The April burst was a long grind against one platform, not a pipe-breaking event on the public internet.

HTTP RATE, TWO CAMPAIGNS APART

Campaign Date Peak HTTP rate Shape
UGC platform flood (DataDome) Mid-April 2026 205,344 rps Five hours, wave modulation
Night Before Christmas max (Cloudflare) December 19, 2025 205 million rps Hyper-volumetric HTTP from Aisuru-Kimwolf

Cloudflare put the December campaign’s average hyper-volumetric HTTP size at 54 million requests per second and separately logged a 31.4 Tbps network-layer hit that lasted 35 seconds. Those are different units from the April HTTP grind, and they belong to a botnet Cloudflare estimates at 1 to 4 million infected hosts, many of them Android TVs.

The billion-count still moved because it is easy to share. The 205,344 figure did not, even though it is the number that tells you this was not a record flood.

Pauses That Reset the Rate-Limit Counters

DataDome said each source averaged one request every nine seconds. At 1.2 million addresses, that pacing alone produces about 133,333 requests per second, close to the measured average, without any one node looking busy.

The operators did not hold a flat firehose. Traffic came in waves, with an opening probe, a rising noisy baseline, and sub-peaks on top. Even the lulls, Segura’s team wrote, ran at tens of thousands of requests per second.

Those gaps were the trick. Aggregate rate-limit windows were allowed to cool, then the next pulse arrived after IP rotation, user-agent swaps, and retuned payloads. A defense that only asks “how many times did this address hit us just now?” watches the wrong clock.

UGC stacks are a soft mark for this shape. Availability is the product, scrapers already probe the same endpoints, and a hit on one surface can spill into others. DataDome listed extortion, disruption, and cover for a second job as the usual motives, and it did not name the customer.

Tor Exits, a Church, and the Big Clouds

The botnet spanned 16,402 autonomous systems, the routing domains that ISPs, clouds, and hosting firms announce. DataDome called that one of the most fragmented profiles it has seen. The mix was flat on purpose: the busiest network held only 3.00% of traffic, so knocking it offline would have left 97% of the flood standing.

TOP ASNS IN THE APRIL FLOOD

Network Share of attack traffic
Stiftung Erneuerbare Freiheit 3.00%
1337 Services GmbH 2.69%
HERN Labs AB 2.27%
Cloudflare, Inc. 1.88%
DigitalOcean, LLC 1.69%
Amazon.com, Inc. 1.44%
QuickPacket, LLC 1.37%
Church of Cyberology 1.21%
Google LLC 1.19%

DataDome flagged Stiftung Erneuerbare Freiheit (Foundation for Renewable Freedom), 1337 Services GmbH, and Church of Cyberology as anonymization-friendly networks. Those three names added up to 6.90% of traffic. Cloudflare, DigitalOcean, Amazon, and Google added up to 6.20%. Household cloud egress sat next to privacy routing, which is the point: a block list aimed at “bad ASNs” has to punch the same providers that carry paying customers.

Stiftung’s registry name, TORSERVERS-NET, is the Tor-exit crowd. 1337 Services GmbH is a Hamburg hosting ASN, AS210558. Church of Cyberology is AS215125, a Dutch non-profit that publishes Church of Cyberology infrastructure notes for a small Amsterdam footprint, including the 192.42.116.0/24 block.

Cloudflare’s own 2025 year-end report already listed cloud platforms such as DigitalOcean, Microsoft, Tencent, Oracle, and Hetzner among the busiest sources of HTTP DDoS on its edge. It offers a free botnet threat feed for providers, and more than 800 networks have signed up. The April table is that same cloud-abuse pattern, only flattened until no single tenant is worth a panic ticket.

The Bots Could Not Hold a Browser Identity

DataDome split the profile in two. The network was huge. The impersonation stack was not. Segura’s write-up calls the actor highly distributed and only moderately sophisticated on evasion, a pairing that should have been in the first headline and was not.

WHAT THE BOTNET FAKED AND SKIPPED

  • Headers and cookies: Forged HTTP headers, cookies, and URL parameters sat on top of basic TLS and server-fingerprint obfuscation.
  • Session churn: Geolocation, browser, and session environment rotated deeply, with IP, timezone, and language often contradicting one another.
  • No real browser: DataDome saw no advanced browser automation and no JavaScript forgery, the usual marks of expert-tier tooling.
  • No residential tradecraft: The team also saw no reactive mobile or residential proxy work, which is a different botnet economy than Aisuru-style home devices.
  • Broken identity: Browser identification signals shifted inside a single session, and TLS handshakes did not match the claimed browser, which no logged-in human does.
  • Old reputation: Source IPs already carried negative scores from earlier abuse on DataDome’s network, so the pool was loud in threat intel even while it was quiet per address.

Each extra fake created a mismatch. A header that does not agree with a TLS fingerprint that does not agree with a timezone is cheaper to catch than a clean headless Chrome farm. The crew spent enough effort to look like a browser in a log line, and not enough to stay one for a whole session.

Why Rate Limits Failed Against 1.2 Million IPs

Each source averaged one request every nine seconds, so no single address tripped a per-IP cap. Wave pauses then reset the aggregate counters, and the next pulse arrived from a rotated pool of user agents and IPs. Blocking the busiest ASN would have cut 3.00% of traffic.

Classic rate limits still assume a noisy neighbor. They count hits from one address, one subnet, or one token in a short window, then drop the rest. That rule dies when the window is full of almost-polite clients and the operator can wait it out.

The April flood was an application-layer DDoS attacks problem, HTTP against pages and APIs, not a bit-pipe contest. Origin workers and app CPUs feel 136,000 rps even when the transit link is fine. A WAF that only ships a requests-per-IP number is counting the wrong object: the session, not the address, is what repeats.

DataDome put it bluntly on the volume-versus-structure split. Static thresholds fail against a rotating 1.2 million-source pool because the signature lives across time and across sources. The peak is obvious in a chart. The per-IP view stays green.

How DataDome Flagged a Pulse No Human Makes

Server-side TLS fingerprints did not match the claimed browsers. Session geolocation contradicted language and timezone. IPs already carried negative reputation. The pulse itself, tens of thousands of requests per second even in the lulls, did not look like human traffic.

The Galileo team did not lean on one switch. Fingerprinting caught network-layer tells that survived the header theater. Behavioral models flagged sequence anomalies and fabricated session state. Threat intel, ranked third among the signals, tagged the dirty addresses, including ones coming out of the anonymization ASNs.

Legitimate traffic at this scale does not pulse.

Jerome Segura, VP of Threat Research, DataDome

DataDome blocked the campaign in real time, then wrote the post. The same note says evasion creates its own signatures: the more layers in the impersonation stack, the more internal contradictions to score. Wave memory matters as much as the instantaneous count, because the operator is tuning live, not dumping a script and walking away.

Per-IP Caps Still Arrive as the Default WAF Rule

Cloudflare counted 47.1 million DDoS events on its network in 2025, a 121% jump, and mitigated 5,376 attacks an hour. Most defenders do not sit on that edge. They inherit a WAF template whose first lever is still “N requests per IP,” then they find out in an incident that N was never the unit that mattered.

The April job is easy to copy on any high-traffic site that still trusts that lever. You need a large, flat proxy pool, a rotator that sleeps on the counter window, and enough header junk to pass a shallow bot check. You do not need JavaScript forgery. You do not need a 205 million rps cannon.

DataDome’s own 2.45 billion requests in five hours write-up is a customer-story with a useful scar. Distribution beat scale. A 3.00% ASN is not a kill switch. A nine-second cadence is not a human browsing a feed, and it is also not a rate-limit event. Until the default control stops asking a single address how busy it is, the next operator can keep the needle in the green and still fill the origin.

Frequently Asked Questions

What is a Layer 7 DDoS attack?

A Layer 7 flood aims at HTTP pages, APIs, and logins, so the application’s CPU, workers, and origin connections fail even when the network pipe still has spare bits. Layer 3 and Layer 4 floods try to fill that pipe with packets or gigabits instead, which is the 31.4 Tbps class Cloudflare logged in December 2025, a different failure mode from the April HTTP grind.

Did the April 2026 botnet use residential proxies?

DataDome said the operator showed no reactive mobile or residential proxy tradecraft and instead mixed anonymization-friendly ASNs with major cloud egress. That is a different supply chain from botnets that rent infected home routers and Android TVs, and it is why a “block the residential ISPs” rule would have missed this pool.

What is an autonomous system in a DDoS, and why did 16,402 of them matter?

An autonomous system is a routing domain, the number an ISP, cloud, or host uses to announce IP space. DataDome said a typical large scrape runs across a few hundred of those domains; a five-figure spread means a firewall rule that drops one ASN, even Stiftung Erneuerbare Freiheit at 3.00%, leaves the rest of the clients untouched.

Did DataDome name the user-generated content platform?

No. The May 5, 2026 research post describes a large-scale UGC customer whose availability, scrapers, and multiple surfaces made it a prime target, and it never publishes the brand, which is why every later recap still talks about an unnamed platform.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending