/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cloudflare says it's spotted massive DDoS amplification attacks that abuse Memcached servers and the UDP protocol, has mitigated attacks of up to 260Gbps

Over last couple of days we've seen a big increase in an obscure amplification attack vector - using the memcached protocol, coming from UDP port 11211.

Cloudflare Blog Marek Majkowski

Context & Ripple Effects

In early 2018, Cloudflare flagged a sudden surge in an obscure amplification technique: attackers sending small spoofed requests to exposed Memcached servers on UDP port 11211 and getting enormous responses reflected at victims, with mitigations reaching 260Gbps. At the time that ranked among the largest floods ever recorded.

The related coverage shows how quickly that bar moved: Cloudflare later absorbed a record 7.3Tbps attack in mid-2025 and, most recently, a 31.4Tbps flood from the Aisuru/Kimwolf botnet in December 2025 — the largest publicly disclosed. The memcached episode is the early chapter of a volumetric arms race that has since shifted from protocol amplification to massive botnets.

First-order effects

  • Operators running Memcached on publicly reachable UDP 11211 are being weaponized as reflectors without their knowledge, while targeted organizations face multi-hundred-gigabit floods that can saturate upstream links until mitigated.

Second-order effects

  • Hosting providers and network operators are pushed to block or scrub outbound spoofed UDP traffic and close exposed memcached ports, shrinking the reflector pool; enterprises meanwhile lean harder on always-on mitigation services like Cloudflare's.

Third-order effects

  • If the trajectory in the coverage holds — from 260Gbps amplification to tens-of-Tbps botnet attacks — DDoS defense becomes a permanent capacity race where providers must provision absorption headroom for record floods that arrive faster than disclosure cycles, and protocol-level hygiene (closing amplification vectors at the source) becomes baseline infrastructure policy.

The trend: DDoS attacks have escalated from hundreds-of-gigabits-per-second amplification abuse like memcached to tens-of-terabits-per-second botnet floods, forcing mitigation providers into a continuous capacity arms race.