Massive DDoS Attack Used 1.2 Million IPs to Bypass Rate Limits

A distributed denial-of-service attack targeting a major user-generated content platform generated 2.45 billion malicious requests in just five hours, making it one of the most sophisticated volumetric attacks observed in recent memory.

Security provider DataDome successfully intercepted the assault in real time, ensuring legitimate users experienced zero disruption throughout the incident.

What set this attack apart was not just its scale, but its architectural cleverness.

Rather than relying on traditional brute-force flooding, the threat actors distributed traffic across 1.2 million unique IP addresses, a deliberate strategy designed to expose fundamental weaknesses in conventional defenses that depend on static thresholds to flag malicious activity.

How Attackers Engineered the Perfect Evasion

The operation peaked at over 200,000 requests per second while sustaining an average of approximately 136,000 requests per second across the full five-hour window.

Each compromised device averaged roughly one request every nine seconds, a calculated pace that ensured no single source ever triggered standard rate-limiting rules.

Instead of a constant barrage, the attackers used a wave pattern, cycling traffic intensity up and down.

During the lulls between waves, security systems’ aggregate counters had time to reset, effectively allowing the attack to remain invisible to conventional threshold-based detection.

This adaptive cadence strongly suggests a managed operation where a human operator was actively monitoring detection signals and adjusting tactics in real time.

Between waves, attackers rotated IP addresses, swapped user agents, and refreshed their payloads. This level of operational discipline indicates purpose-built tooling and significant coordination, not an off-the-shelf botnet running on autopilot.

Attack traffic observed  (Source: DataDome)
Attack traffic observed  (Source: DataDome)

To execute an attack of this magnitude, the threat actors leveraged infrastructure spanning more than 16,000 autonomous systems.

The traffic distribution was strikingly flat; the highest-contributing single network accounted for only 3% of total volume.

This deliberate fragmentation made blanket IP-range blocking completely ineffective.

The attackers further camouflaged their footprint by routing traffic through mainstream cloud providers, including Cloudflare, Amazon, and Google, mixing it with traffic from privacy-oriented and obscure networks such as 1337 Services GmbH and Church of Cyberology.

By blending recognizable, legitimate-looking traffic sources with anonymization-friendly networks, they created a complex infrastructure web that rendered standard IP reputation blocking useless.

Defenders successfully identified and neutralized the threat by moving beyond aggregate traffic analysis and instead focusing on behavioral baselines and session-level anomalies.

Server-side fingerprinting revealed critical inconsistencies between the browser environments the attack traffic claimed to represent and the actual characteristics observed at the network layer.

Legitimate browsers maintain consistent internal signals throughout a session, but the automated tools used in this attack exhibited shifting identification markers within individual sessions, a telltale sign of synthetic, bot-generated traffic.

Security systems also analyzed session sequence anomalies, looking at how requests were ordered and timed within individual connections.

The fabricated browser environments contained internal contradictions that no real user session would produce.

By correlating these behavioral signals with threat intelligence feeds, DataDome’s systems could classify traffic as malicious with high confidence, even when no individual IP address exceeded a suspicious request volume.

The result was complete mitigation across all platform segments without a single legitimate user being impacted, a significant operational achievement given the attack’s complexity.

The adversary profile that emerges is a highly distributed but moderately sophisticated attacker who prioritized raw throughput and detection evasion over stealth at the individual node level.

The operation demonstrates that volumetric DDoS attacks have evolved well beyond simple flooding.

Modern attacks require defenders to invest in deep behavioral analysis, session-level fingerprinting, and real-time threat intelligence rather than relying on rate limits alone.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories