Microsoft Azure blocked a record-breaking 15.72 terabit-per-second distributed denial-of-service attack on Oct. 24, TechRepublic reported. The assault targeted a single endpoint in Australia and generated nearly 3.64 billion packets per second.
Azure DDoS Protection detected and mitigated the multi-vector incident automatically, keeping cloud services and customer workloads online throughout the event. Sean Whalen, senior product marketing manager at Azure Security, confirmed in a blog post that the incident was the largest DDoS attack ever observed in the cloud.
Microsoft traced the traffic to the Aisuru botnet, an IoT malware strain derived from Mirai. The attack mobilized more than 500,000 IP addresses across multiple regions, relying on compromised home routers and connected cameras located primarily on residential internet service providers in the United States and other countries.
Attack mechanics and botnet history
Attackers directed rapid bursts of UDP packets against the Australian target using randomized ports and minimal source spoofing. Microsoft absorbed and filtered the malicious flow in real time through its global network of scrubbing centers.
The Aisuru botnet has been tied to multiple high-volume incidents across the cybersecurity sector. Cloudflare linked the same botnet to a 22.2 Tbps attack earlier in the year, and security researchers at Qi’anxin previously tracked an 11.5 Tbps strike to the group. Whalen noted that faster fiber-to-the-home connections and higher-capacity consumer hardware have continued to push baseline attack sizes upward.
Microsoft warned organizations not to delay defense testing until an attack occurs, urging them to conduct regular operational drills and simulations ahead of anticipated traffic surges during end-of-year shopping periods.
