26M rps HTTPS Attack: Anatomy of a Record DDoS

Cloudflare has disclosed that it automatically detected and mitigated a 26 million request per second (rps) HTTPS DDoS attack — the largest such attack on record. The incident targeted a website on Cloudflare's Free plan and was stopped by the company's HTTP DDoS Managed Ruleset, powered by its autonomous edge protection systems.

The attack follows a pattern of escalating record-breaking DDoS events over the past year. Cloudflare previously reported a 17.2M rps HTTP DDoS attack in August 2021 and a 15M rps HTTPS attack in April 2022. This latest incident stands out not only for its peak volume but for the relatively small botnet that generated it.

Cloudflare mitigates 26 million request per second DDoS attack

Small Botnet, Disproportionate Firepower

The 26M rps attack was launched by a botnet of just 5,067 devices, averaging roughly 5,200 requests per second per node at peak. For context, Cloudflare has been tracking another botnet of over 730,000 devices that could only muster about 1.3 rps per device. The smaller botnet was, on average, roughly 4,000 times more powerful per node.

The reason for the disparity: the attack originated primarily from cloud service providers rather than residential ISPs. This points to the use of hijacked virtual machines and powerful servers — not IoT devices — as the attack infrastructure.

Notably, this was an HTTPS attack. Encrypted HTTPS DDoS attacks are significantly more resource-intensive than their plaintext HTTP counterparts, given the computational cost of establishing TLS connections. The scale of this attack implies a substantial investment in computational resources on the attacker's part.

Within under 30 seconds, the botnet generated more than 212 million HTTPS requests from over 1,500 networks across 121 countries. The most common source countries were Indonesia, the United States, Brazil and Russia, with approximately 3% of traffic coming through Tor nodes.

Top source networks included:

  • OVH (ASN 16276), France
  • Telkomnet (ASN 7713), Indonesia
  • iboss (ASN 137922), US
  • Ajeel (ASN 37284), Libya

The attack spanned a wide range of global networks, with over 1,500 ASNs involved in the campaign. Notably, the vast majority of the source networks were cloud providers and hosting companies — not residential ISPs — which is consistent with the use of compromised infrastructure rather than consumer devices.

Cloudflare has since named the botnet "Mantis," drawing a comparison to the mantis shrimp: small in size but disproportionately powerful. The botnet has remained active since the record attack, targeting VoIP and cryptocurrency properties with HTTPS DDoS attacks up to 9M rps.

Cloudflare's recent DDoS trends data paints a picture of an evolving threat landscape. Most attacks are small — the kind of cyber vandalism that can still take down unprotected properties. Meanwhile, large attacks are increasing in both size and frequency, but tend to be short and fast, concentrating their power into a quick knockout blow to avoid detection.

This dynamic has a critical implication for defensive strategies. Since attacks are machine-generated and often over before human responders can act, automated always-on protection is essential. Even brief attacks can leave behind prolonged network issues and application failures, affecting revenue and reputation well after the traffic stops.

The company's stated goal is to make the impact of DDoS attacks a thing of the past, with mitigation services that are unmetered and not bounded by attack size, duration or frequency — a stance that matters more as attacks continue to grow in scale and sophistication.