The world of connected services has just been rocked by an incident of unprecedented scale. In a coordinated attack that simultaneously knocked multiple major networks offline, cyber security analysts have confirmed a new global record for the largest Distributed Denial of Service (DDoS) attack ever recorded.
The disruption began on October 6th, when players across various PC platforms experienced sudden, debilitating lag and total disconnections. A few hours later, in the early morning of October 7th, a second wave crashed down, demonstrating the scope and sophistication of the operation.
The Unbelievable Scale of the Attack
This wasn't a minor server hiccup. This was a direct, calculated cyber assault that peaked at an almost unbelievable 29.69 terabits per second (Tbps) of junk traffic. To put that into perspective, this single event shattered the previous high of 22.2 Tbps, showcasing a dangerous escalation in the capabilities of cyber threat actors.
The fallout was instant and widespread, affecting millions of users across critical online infrastructure. Platforms hit included:
PlayStation Network (PSN): The service was severely impacted, with Down Detector recording nearly 9,000 peak user reports. The primary issue reported was an 82% server connection failure rate.
PC Platforms: Steam and Riot Games were among the first to see critical issues. Steam users reported frustration as "cloud sync wasn't working properly" and store pages failed to load. Riot Games temporarily disabled ranked queues in an effort to stabilize service.
Wider Infrastructure: The attack's non-selective nature meant other services were also affected, including the Xbox network, Epic Games (and Fortnite), Battle.net, and broader infrastructure providers like AWS and streaming services such as Hulu.
By midafternoon on October 7th, services began a slow recovery, but reports persist of lingering issues, such as Steam cloud sync failures.
The Culprit: The Aiseru Botnet
Cyber security experts are unanimous in their consensus: this was a massive DoS attack, designed to overwhelm network capacity and render legitimate user requests impossible. The main culprit being pointed to is the notorious Aiseru botnet.
First disclosed by cyber security researchers at XLAB in August 2024, Aiseru is described as the largest active botnet in existence, controlling around 300,000 compromised devices worldwide. Crucially, these aren't high-end servers; they are everyday consumer devices like home routers, DVRs, and cameras that have been infected and weaponized.
Experts detailed the sophisticated nature of the traffic, describing it as a mix of "sophisticated TCP carpet bomb attacks and volumetric floods." According to XLAB's research, the Aiseru group is highly organized, led by three key figures:
Snow: Responsible for botnet development.
Tom: Focused on finding system vulnerabilities.
Forky: Manages sales and marketing for the operation.
While the group has been known to launch attacks for fun, some past operations have included ideological messaging. Whether this mass platform outage was a targeted assault on gaming specifically or merely a flex of power or stress test before a larger target remains a major topic of debate among security analysts.
This incident serves as a stark reminder of the digital fragility of our infrastructure, dwarfing past high-profile outages, such as the infamous 2014 attacks by Lizard Squad that hit both PSN and Xbox. Experts from XLAB and other firms are urging users to take critical steps now: regularly patching and updating the firmware on home routers, smart doorbells, and other connected tech. By failing to secure these devices, users risk unknowingly becoming one of the 300,000 silent soldiers in the next record-breaking attack.
Comments
Post a Comment