Cloudflare says it's spotted massive DDoS amplification attacks that abuse Memcached servers and the UDP protocol, has mitigated attacks of up to 260Gbps
Over last couple of days we've seen a big increase in an obscure amplification attack vector - using the memcached protocol, coming from UDP port 11211.
Context & Ripple Effects
In early 2018, Cloudflare flagged a sudden surge in an obscure amplification technique: attackers sending small spoofed requests to exposed Memcached servers on UDP port 11211 and getting enormous responses reflected at victims, with mitigations reaching 260Gbps. At the time that ranked among the largest floods ever recorded.
The related coverage shows how quickly that bar moved: Cloudflare later absorbed a record 7.3Tbps attack in mid-2025 and, most recently, a 31.4Tbps flood from the Aisuru/Kimwolf botnet in December 2025 — the largest publicly disclosed. The memcached episode is the early chapter of a volumetric arms race that has since shifted from protocol amplification to massive botnets.
First-order effects
- Operators running Memcached on publicly reachable UDP 11211 are being weaponized as reflectors without their knowledge, while targeted organizations face multi-hundred-gigabit floods that can saturate upstream links until mitigated.
Second-order effects
- Hosting providers and network operators are pushed to block or scrub outbound spoofed UDP traffic and close exposed memcached ports, shrinking the reflector pool; enterprises meanwhile lean harder on always-on mitigation services like Cloudflare's.
Third-order effects
- If the trajectory in the coverage holds — from 260Gbps amplification to tens-of-Tbps botnet attacks — DDoS defense becomes a permanent capacity race where providers must provision absorption headroom for record floods that arrive faster than disclosure cycles, and protocol-level hygiene (closing amplification vectors at the source) becomes baseline infrastructure policy.
The trend: DDoS attacks have escalated from hundreds-of-gigabits-per-second amplification abuse like memcached to tens-of-terabits-per-second botnet floods, forcing mitigation providers into a continuous capacity arms race.