TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Analysis of a Large-Scale DDoS Attack Against a Payment Processing Platform

2025-11-19 · Read original ↗

ATT&CK techniques detected

9 predictions
T1498.001Direct Network Flood
86%
"of the ips, which reached 12 mpps before dissipating within two minutes. the most intense stage of this initial assault began at 17 : 30 utc, when the attackers escalated the psh - ack flood to reach a peak of 1. 8 tbps ( terabits per second ) and 158 mpps. this surge lasted appr…"
T1498Network Denial of Service
85%
"analysis of a large - scale ddos attack against a payment processing platform introduction on saturday, september 13, 2025, a major distributed denial - of - service ( ddos ) attack targeted a european payment processing platform, prompting response and mitigation efforts by the …"
T1498.001Direct Network Flood
77%
"analysis of a large - scale ddos attack against a payment processing platform introduction on saturday, september 13, 2025, a major distributed denial - of - service ( ddos ) attack targeted a european payment processing platform, prompting response and mitigation efforts by the …"
T1498Network Denial of Service
63%
"on the part of the attackers. the use of volumetric psh - ack floods, first with unique packet sizes and later with standard - sized packets, indicates an effort to evade detection and bypass existing mitigation measures. the adoption of small ack packets in the second wave to dr…"
T1498.001Direct Network Flood
58%
"on the part of the attackers. the use of volumetric psh - ack floods, first with unique packet sizes and later with standard - sized packets, indicates an effort to evade detection and bypass existing mitigation measures. the adoption of small ack packets in the second wave to dr…"
T1498Network Denial of Service
49%
"of the ips, which reached 12 mpps before dissipating within two minutes. the most intense stage of this initial assault began at 17 : 30 utc, when the attackers escalated the psh - ack flood to reach a peak of 1. 8 tbps ( terabits per second ) and 158 mpps. this surge lasted appr…"
T1499Endpoint Denial of Service
48%
"analysis of a large - scale ddos attack against a payment processing platform introduction on saturday, september 13, 2025, a major distributed denial - of - service ( ddos ) attack targeted a european payment processing platform, prompting response and mitigation efforts by the …"
T1498.001Direct Network Flood
45%
"phase introduced a combination of repeated psh - ack floods and a subsequent flood of acknowledgment ( ack ) packets. the attackers reverted to their standard psh - ack packet size of 1440 bytes but introduced smaller ack packets, measuring merely 49 - 50 bytes each. this variabl…"
T1499Endpoint Denial of Service
45%
"on the part of the attackers. the use of volumetric psh - ack floods, first with unique packet sizes and later with standard - sized packets, indicates an effort to evade detection and bypass existing mitigation measures. the adoption of small ack packets in the second wave to dr…"

Summary

The two-wave attack reached a peak of 1.8 Tbps.