Meris: The Router Botnet Behind Record-Breaking DDoS Attacks

In July 2021, Cloudflare detected and mitigated a 17.2 million requests per second (rps) DDoS attack—the largest ever reported at the time. The attack originated from a botnet that has since become known as Meris, named after the Latvian word for plague. Since then, Cloudflare's automated DDoS protection systems have continued to detect and neutralize attacks from this botnet, with all customers, including those on the free plan, remaining protected.

Analysis of Meris activity over several months reveals a persistent and evolving threat. The botnet launches an average of 104 unique DDoS attacks daily against roughly 50 different websites. A significant portion of its attack traffic—more than 33%—is directed at China-based websites, while over 12% of the websites it targets are operated by US-based companies.

The Anatomy of the Botnet

Meris is composed of infected routers and networking hardware from the Latvian manufacturer MikroTik. The attackers exploit a directory traversal vulnerability, tracked as CVE-2018-14847, in the WinBox configuration interface of MikroTik's RouterOS. This vulnerability enables unauthenticated remote access to the file system, allowing attackers to read administrative files and write malicious ones to conscript the devices into the botnet.

While this vulnerability was patched in 2018, it remains exploitable in devices running unpatched RouterOS versions or those still using default credentials. MikroTik has advised customers to upgrade their operating systems, restrict access to secure IPsec connections, and check for anomalies such as unknown SOCKS proxy settings or scripts. Initial research by QRator and Yandex identified between 30,000 and 56,000 active bots, with estimates suggesting the total could be as high as 250,000.

The botnet generates volumetric attacks through HTTP pipelining, which sends multiple requests over a single connection to boost overall attack throughput. To obscure the source of these attacks, Meris routes traffic through open SOCKS proxies. Cloudflare's mitigation includes a 'Connection Close' action that neutralizes the effectiveness of HTTP pipelining. Additionally, Cloudflare provides a Managed IP List of Open SOCKS Proxies, which customers can incorporate into firewall rules to block, challenge, or rate-limit traffic from these proxies.

Comparison with Mirai

Meris is often compared to the Mirai botnet, which made headlines around five years ago for record-breaking attacks using hundreds of thousands of compromised IoT devices. Variants of Mirai, such as Moobot, have continued to launch substantial attacks, including a 654 Gbps assault last year and a resurgence of UDP and TCP-based attacks peaking above 1 Tbps.

The key distinction lies in the hardware. Mirai infected low-power IoT devices, whereas Meris conscripts routers with significantly higher processing power and data transfer capabilities. This makes Meris substantially more potent, capable of inflicting harm on unprotected web properties at a much larger scale.

Attack Patterns and Evolution

Cloudflare's security teams observed Meris attacks adapting over time in attempts to bypass defenses. While these attempts were unsuccessful, Cloudflare engineers deployed additional mitigation rules in early August to provide more comprehensive protection. These rules also yielded granular threat intelligence on Meris activity.

Since the deployment of these new rules, Meris has launched an average of 104 DDoS attacks daily against Cloudflare customers. A notable spike occurred on September 6, when the botnet launched 261 unique attacks in a single day. On that day, Meris accounted for a record-breaking 17.5% of all Layer 7 DDoS attacks observed by Cloudflare. While the average attack peaked at 106K rps, the median attack size was 17.6K rps. The largest attack mitigated since the new rules were deployed was a 16.7M rps assault on August 19.

Target Industries

The Banking, Financial Services, and Insurance (BFSI) industry received the most attack traffic from Meris. Following BFSI were the Publishing, Gaming/Gambling, and IT Services industries. However, when ranked by the percentage of targeted websites, the Computer Software industry came first at nearly 4%, followed by Gaming/Gambling at 3% and IT Services at 2%.

Attack patterns over time reveal peaks aligned with public interest events. Two of the largest bursts, on August 9 and August 29, were directed at Computer Software, Gaming/Gambling, and IT companies. A notable spike on August 14 targeted Cryptocurrency providers. Late August saw significant waves of attacks—reaching hundreds of thousands to millions of rps—against gambling and casino websites, with a second wave launching in early September.

Geographic Targeting and Bot Distribution

When measured by attack traffic volume, China was the primary target, receiving over 33% of all Meris requests destined for Cloudflare-protected companies. Australia and the US followed in second and third place. However, looking at the number of targeted websites, the US ranked first, with more than 12% of all attacked websites operated by US-based companies. China and Russia followed at 5.6% and 4.4%, respectively.

The geographic distribution of the bots themselves changed significantly over the observed period. At the start of August, most bots were located in Brazil, but by the end of the month, that figure had plummeted to near zero. Concurrently, the number of infected devices in the US grew. By September, higher bot counts were observed in the US, Russia, India, Indonesia, and China. These shifts may reflect the activation of different bot groups over time rather than simple growth or decline of the botnet.

Autonomous Protection

Cloudflare's autonomous DDoS protection systems automatically detect and mitigate attacks from Meris, Mirai, and other botnets. These systems are configurable, allowing customers to tailor HTTP DDoS protection via the HTTP DDoS Managed Ruleset and Layer 3/4 mitigation through the L3/4 DDoS Managed Ruleset.