Akamai reported the first observed in-the-wild DDoS attacks using TCP Middlebox Reflection, a technique that abuses vulnerable firewalls, deep packet inspection devices, content-filtering systems, and censorship-related middleboxes to reflect and amplify traffic toward victims. The activity marked the practical weaponization of an attack path that had previously been discussed largely as a theoretical risk, with campaigns beginning around February 17 and hitting organizations in banking, travel, gaming, media, and web hosting.
In one case, a single TCP SYN packet with a 33-byte payload triggered a 2,156-byte response, producing roughly 65x amplification and lowering the bandwidth attackers need for volumetric attacks. Akamai observed attack traffic peaking at 11 Gbps and 1.5 million packets per second, underscoring that amplification threats are no longer limited to the better-known UDP-based reflection methods tracked by defenders and government agencies, and that mitigation strategies must now account for abuse of TCP-handling middleboxes as well.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
An academic study published in August 2021 described a TCP-based reflected denial-of-service amplification vector that abuses protocol-noncompliant middleboxes. This established the technique before it was later observed in real-world attacks.
Akamai reported the first observed real-world DDoS attacks using TCP Middlebox Reflection, marking the shift of the technique from theory to practice. In observed campaigns, traffic peaked at 11 Gbps and 1.5 million packets per second, and one case showed a 33-byte SYN packet triggering a 2,156-byte response for roughly 65x amplification.
Akamai said the first noticeable in-the-wild campaigns using TCP Middlebox Reflection began around February 17. The attacks targeted customers in banking, travel, gaming, media, and web hosting, and were observed both as standalone and multi-vector DDoS activity.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceakamai.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.