A major user-generated content platform was hit by a highly distributed low-and-slow DDoS campaign that generated 2.45 billion malicious requests in five hours, peaking at 205,344 requests per second and averaging about 136,000 requests per second. According to DataDome’s Galileo threat research team, the operation relied on more than 1.2 million unique IP addresses spread across 16,402 ASNs, with no single network contributing more than 3% of the traffic. The attackers used a pulsed cadence and kept per-IP activity low—roughly one request every nine seconds on average—to stay below conventional rate-limiting thresholds and make simple IP blocking ineffective.
The traffic was designed to resemble legitimate users by rotating IPs, user agents, and payloads and by forging HTTP headers, cookies, and TLS fingerprints. Researchers said the botnet also blended traffic through anonymization-friendly providers and major cloud infrastructure including Cloudflare, AWS, and Google, complicating filtering efforts. DataDome reported that it detected and blocked the attack in real time using behavioral analysis, server-side fingerprinting, and threat intelligence, finding inconsistencies between claimed browser identities and actual TLS handshake behavior. The incident underscores how modern DDoS operators are shifting from brute-force floods to distributed evasion techniques that require time-based behavioral detection rather than static volume limits.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
By early May 2026, DataDome publicly disclosed technical details of the incident and concluded that defenders should prioritize time-based behavioral detection over static rate limits for similarly fragmented DDoS attacks. The report highlighted the growing use of highly distributed, low-and-slow evasion techniques.
DataDome's Galileo threat research team identified the attack in real time and blocked it using behavioral analysis, server-side fingerprinting, and threat intelligence rather than static volume thresholds. Researchers said inconsistencies in TLS handshakes and browser-identification signals exposed the bots despite their attempts to blend in.
During the campaign, the botnet spread traffic across more than 1.2 million unique IP addresses and 16,402 ASNs, with no single network contributing more than 3% of the volume. Operators also rotated IPs, user agents, payloads, forged HTTP headers, cookies, and TLS fingerprints to imitate legitimate browsers and frustrate simple blocking.
In mid-April 2026, a highly distributed DDoS campaign targeted a major user-generated content platform, sending 2.45 billion malicious requests over roughly five hours. The attack peaked at 205,344 requests per second and used a low-and-slow pattern to stay below typical per-IP rate-limiting thresholds.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.