Australian universities hit by pro-Russian hacktivist DDoS wave

Cloudflare has detected HTTP DDoS attacks against Australian university websites over the past 24 hours. The attacks coincide with a Telegram post from the pro-Russian hacktivist group Killnet and its affiliate AnonymousSudan, which named 8 universities, 10 airports, and 8 hospital websites in Australia as targets beginning Tuesday, March 28.

Killnet and AnonymousSudan DDoS attack Australian university websites, and threaten more attacks — here’s what to do about it

The groups described the universities as an opening target, with aviation and healthcare organizations listed for follow-up strikes.

Who is behind the attacks

Killnet is not a conventional hacking collective. It has no formal membership, no proprietary infrastructure, and no financial motive. Instead, it operates as an open Telegram channel where pro-Russian sympathizers volunteer to participate in cyberattacks against Western interests. The group emerged shortly after the IT Army of Ukraine and closely mirrors its operational playbook: administrators issue calls for volunteers to attack selected targets, participants share tools and techniques, and more experienced members coach novices in attack execution.

AnonymousSudan, a similarly unstructured group claiming Sudanese "hacktivist" credentials, has recently begun collaborating with Killnet on attacks against Western organizations.

These latest campaigns do not appear to originate from a single botnet. The attack methods and sources vary, which suggests involvement from multiple individuals with differing levels of skill — a pattern consistent with Killnet's past activity. In February 2023, a Killnet-affiliated group targeted US healthcare organizations, following October 2022 attacks on US airport websites and a November 2022 strike on the US Treasury.

Rising attack scale

DDoS attacks aim to saturate networks with malicious traffic, disrupting service availability or taking systems offline. The scale, sophistication, and frequency of such attacks have climbed steadily. Cloudflare recently intercepted the largest DDoS attack on record, peaking at 71 million requests per second — 54% higher than the previous record set in June 2022.

For organizations with limited security resources, the growing audacity of groups like Killnet signals an elevated threat landscape. Attackers are increasingly comfortable going after high-profile, critical infrastructure, making preparedness a necessity rather than an option.

Cloudflare reports that its systems have been automatically detecting and mitigating these attacks, and that monitoring continues with countermeasures deployed as needed. The company advises customers in the Education, Travel, and Healthcare industries to follow these additional precautions:

  1. Keep all DDoS Managed Rules at default settings — High sensitivity level with mitigation actions enabled.
  2. Enterprise customers with Advanced DDoS protection should consider enabling Adaptive DDoS Protection.
  3. Deploy firewall rules and rate-limiting rules to enforce a combined positive and negative security model, reducing allowed traffic based on known usage patterns.
  4. Enable Bot Fight Mode or the equivalent tier available to your subscription.
  5. Verify the origin server is not publicly exposed — restrict access to Cloudflare IP addresses only.
  6. Maximize caching to relieve strain on origin infrastructure, and avoid excessive subrequest loads on origin servers when using Workers.
  7. Activate DDoS alerting for early warning on potential incidents.

DDoS protection should not require expert staffing or manual intervention. Automated detection and mitigation are essential because real-time human response puts defenders at a disadvantage. Since 2017, Cloudflare has provided unmetered, unlimited DDoS protection to all customers at no charge, reflecting the view that defense against these attacks should be accessible to organizations regardless of size. Periodic threat landscape summaries are available in the Cloudflare DDoS Threat Report for those tracking quarterly attack trends.