惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Simon Willison's Weblog
Simon Willison's Weblog
Vercel News
Vercel News
博客园_首页
酷 壳 – CoolShell
酷 壳 – CoolShell
M
MIT News - Artificial intelligence
The Cloudflare Blog
N
Netflix TechBlog - Medium
GbyAI
GbyAI
Help Net Security
Help Net Security
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
I
Intezer
Martin Fowler
Martin Fowler
量子位
P
Palo Alto Networks Blog
Security Latest
Security Latest
Attack and Defense Labs
Attack and Defense Labs
WordPress大学
WordPress大学
H
Help Net Security
C
Check Point Blog
T
Troy Hunt's Blog
C
CERT Recently Published Vulnerability Notes
Y
Y Combinator Blog
NISL@THU
NISL@THU
L
LINUX DO - 最新话题
V
Visual Studio Blog
C
Cisco Blogs
C
CXSECURITY Database RSS Feed - CXSecurity.com
S
Securelist
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
T
The Exploit Database - CXSecurity.com
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Recent Announcements
Recent Announcements
Forbes - Security
Forbes - Security
IT之家
IT之家
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Application and Cybersecurity Blog
Application and Cybersecurity Blog
L
LangChain Blog
AWS News Blog
AWS News Blog
N
News and Events Feed by Topic
Stack Overflow Blog
Stack Overflow Blog
H
Hacker News: Front Page
B
Blog
W
WeLiveSecurity
罗磊的独立博客
Jina AI
Jina AI
博客园 - 【当耐特】

A10 Networks

Secure, High-Performance Networking Solutions | A10 Battling Bots, Fraud & AI Threats Summit | Retail IT & Cybersecurity What Is Healthcare Data Compliance? | A10 Networks Interop Best of Show Runner's Up - People's Choice | A10 Networks Interop Best of Show Runner's Up - Security for AI | A10 Networks What Is FIX Protocol Trading? | A10 Networks A10 Joins OpenAI's Trusted Access for Cyber Flexible Licensing for Multiple Clouds | A10 Networks A10 Acquires TrojAI to Advance Enterprise AI Security HFT Infrastructure: High Frequency Trading Explained | A10 Networks A10 Networks Acquires TrojAI Inc., Expanding AI Roadmap | A10 Networks What Is Low-latency Trading? | A10 Networks Multi-Vector DDoS: 11 Amplification Vectors | A10 Healthcare Cloud Compliance: HIPAA & GDPR Guide | A10 LLM Unbounded Consumption & DoS Attacks | OWASP LLM10 LLM Hallucination & Misinformation | OWASP LLM09:2025 Healthcare Network Protection for Hospitals & Clinics RAG Security: Vector & Embedding Weaknesses | OWASP LLM08 System Prompt Leakage | OWASP LLM07:2025 Explained LLM Excessive Agency | OWASP LLM06:2025 Explained LLM Supply Chain Security | OWASP LLM03:2025 Trust, Control and Security in the Age of Agentic AI Summit | A10 Networks LLM Improper Output Handling | OWASP LLM05:2025 Data Poisoning Attacks in LLMs | OWASP LLM04:2025 Sensitive Information Disclosure | OWASP LLM02:2025 Game Over for DDoS Attacks in Gaming | How to Achieve Resilience Prompt Injection | OWASP LLM01:2025 Explained Beyond PCI Summit: Battling Bots, Fraud, and AI-powered Threats Web Application Security Best Practices for 2026 | A10 Networks A10’s 5 Key Takeaways on Application & API Security Trends Securing Financial Applications in the AI Era Summit Unified Application Delivery, Security, and AI Protection for Financial Services The Most Famous DDoS Attacks in History Post-quantum Cryptography Comes to A10 SSL/TLS Data Plane Real-time DDoS Carpet-bombing: NTP Amplification Evasion Shadow AI | Glossary AI & LLM Security: Hype vs. Reality and What to Prioritize App Delivery in the Age of AI Summit | Hybrid & Cloud-Native Strategies A Day in the Life of a Stressed Web Application | ADC & WAF Resilience Avans University of Applied Sciences Modernizes Hybrid Application Delivery with A10 Networks Preparing Government Infrastructure for AI Adoption | Expert Summit Report: IDC Spotlight Report: Modernizing Application Delivery Infrastructure for AI-powered Applications Broken Object Level Authorization (BOLA): The #1 API Security Risk | Free Webinar | A10 Networks Product Demo: A10 AI Firewall by A10 Networks AI Firewall for Enterprise AI Security | A10 Networks API Traffic Management for AI and Agentic Systems | Expert Summit AI is Here: How Ready Is Your Infrastructure? | A10 Networks Tech Companies Lead GenAI Adoption but Face Infrastructure Gaps Cyber Defense Magazine's 2026 Global InfoSec award – Editor's Choice – API Security | A10 Networks Load Balancing Solutions for Availability & Security | A10 Networks Top 9 Generative AI Security Risks in 2026 LLM Security: Protecting AI Models & Applications
Pulse Campaign Analysis: Brazil ISPs Expose Next-Gen DDoS Automation Trends
2026-04-02 · via A10 Networks

A10 AI Firewall chart showing features: Easy to Deploy, Out-of-the-Box LLM Security, AI Governance, Kubernetes Ready.

A pattern hiding inside the noise of 498,163 attacks, captured from March 14, 2026-March 20, 2026, and what it means for every regional ISP on the planet

Roughly 79 percent of these attacks are CLDAP. Nearly all are targeting Brazilian ISPs but filter out the noise and look at what is happening at the ISP level. Something immediately stands out.

The same small cluster of telecom organizations as mentioned in the prior A10 blog and several other smaller regional operators — is being hit across dozens of /24 subnet blocks simultaneously, with attack durations clustering in a remarkably tight band: 29 to 60 seconds, repeating in waves seconds apart.

This is not random. An attack lasting 29 seconds, followed by another at 39 seconds, followed by another at 59 seconds across six different subnet ranges from the same ISP, all within a 90-second window is not a human pressing buttons. It is a script with a timer. The data is showing that the operational signature of automated pulse-fire DDoS infrastructure is likely a DDoS-for-hire service or a botnet module running a configured attack loop.

The 29-60-second duration cluster is particularly telling: short enough to evade some per-connection duration thresholds and long enough to saturate upstream links for every customer on those /24 blocks. And it’s repeated with mechanical precision across subnets, suggesting the attacker isn’t targeting a single IP — it’s targeting the ISP’s access infrastructure in aggregate.

This is the carpet-bombing pattern that the prior A10 blog identified in February. The March data reveals that it hasn’t stopped. It has intensified.

CLDAP is the Weapon of Choice — And That’s No Coincidence

In Q1 2025, Cloudflare recorded a 3,488 percent quarter-over-quarter increase in CLDAP reflection and amplification attacks — a staggering number that most defenders didn’t act on quickly enough. CLDAP’s amplification factor of 56 to 70 times the original request means attackers no longer need to maintain large botnet infrastructures; they can leverage open CLDAP servers on the internet to generate a massive influx of data at the victim’s IP.

A CLDAP DDoS reflection attack has an amplification factor of up to 70x, making it one of the most effective UDP protocols for abuse. For a threat actor running a DDoS-as-a-service platform, these are ideal economics: a small investment in spoofed query traffic, an enormous return in volumetric payload, no botnet up-keep.

Critically, Brazil has historically had a large number of exposed CLDAP services with over 5,400 distinct IP addresses running CLDAP openly accessible on the internet via port 389. This creates a grim feedback loop: Brazilian infrastructure is both a primary victim and a potential reflector pool, making the country’s ISPs doubly exposed.

The Parallel Campaign Targeting Europe

While the Brazilian CLDAP wave rolls on, the same reporting window shows high-severity NTP attacks targeting European telecom operators with complexity ratings of “high” and durations running up to 563 seconds.

This is not a coincidence of timing. Two things are happening in parallel: a low-complexity, high-volume, automated pulse campaign against underprepared regional ISPs in Brazil and a targeted high-severity amplification campaign against European carriers. Different tools, different geographies, different severity levels — but the same reporting window.

This multi-geography, multi-vector structure is consistent with what we would expect from a mature threat actor or a DDoS platform serving multiple customers simultaneously. It is also consistent with what Cloudflare described in their record-breaking attack analysis: in April 2025, a hyper-volumetric, multi-vector attack occurred at 6.5 Tbps and used more than 30,000 unique IP addresses from 147 countries and multiple attack vectors, including CLDAP and SSDP reflection and amplification alongside Mirai botnet traffic. Multi-vector, multi-geography coordination is now the baseline for sophisticated DDoS campaigns — not the exception.

Why Regional ISPs are the Soft Underbelly

The same ISP names appeared dozens of times within minutes. This is not because those organizations are uniquely important strategic targets. It is because they are the easiest targets on the map.

Small regional fiber ISPs in Brazil and everywhere else operate on thin margins with commodity routing hardware and no dedicated scrubbing infrastructure. They rely on upstream transit providers who may not offer proactive DDoS mitigation. They don’t have 24/7 NOC teams watching for carpet-bombing patterns across /24 blocks. And critically, when their access links get saturated, the impact is not contained to one customer. It takes down an entire local network — businesses, schools, health services, emergency infrastructure.

A10 research has confirmed that CLDAP, while representing only 0.2 percent of global amplifiers, carries an amplification factor that makes each exposed server disproportionately dangerous. Attackers can send small, spoofed requests to exposed CLDAP servers, which generate responses to the victim of up to 70 times the size of the initial request.

The attacker doesn’t need many weapons. It just needs to find the targets without defenses. Brazil’s regional ISPs are providing exactly that.

The 29-60-Second Signature: What Defenders Need to Watch for

The pulse-fire duration signature in this dataset is actionable threat intelligence. If your network monitoring is configured to alert on sustained attacks exceeding five minutes, this campaign will fly below your radar entirely. The attacker is deliberately staying in the sub-minute range.

Effective detection requires:

  • Aggregate /24 subnet monitoring, not per-IP monitoring: The attacker is distributing load across an entire subnet to avoid per-IP detection thresholds. If you’re only alarming on individual IP traffic volumes, you will miss the access-link saturation that is already occurring.
  • Duration-independent volume alerting: A 35-second burst that saturates your upstream link is just as damaging as a 10-minute sustained attack. Alerting logic must be sensitive to short, repeated bursts across multiple source IPs in the same subnet window.
  • Pre-negotiated upstream RTBH agreements: Remote Triggered Black Hole routing with community tagging must be established with your transit providers before an attack, not during one. During a 35-second pulse, there is no time to make a phone call.
  • Peer intelligence sharing: The organizations being hit in this dataset are neighbors — same country, same tier, same exposure profile. An attack wave that hit INNOVANET’s subnets at 17:29 will hit the next ISP’s subnets minutes later. Formalized threat intelligence sharing between regional ISPs in the same geography can provide the early warning that individual monitoring
  • cannot.

The Bottom Line

A mature, automated pulse-fire campaign is running against Brazil’s regional ISP layer with mechanical precision, using CLDAP amplification and a sub-60-second attack rhythm designed to evade standard detection thresholds. This is running in parallel with high-severity NTP attacks against European carriers in the same window.

The attackers have done their reconnaissance. They know which organizations have mitigation and which ones don’t. The pulse campaign targeting Brazilian regional ISPs exists precisely because those organizations remain undefended and unmonitored at the aggregate subnet level.


Data source: A10 Defend Threat Control, March 14-20, 2026. External validation: Cloudflare Q1 2025 DDoS Threat Report, Akamai CLDAP Reflection DDoS analysis, A10 Networks 2025 DDoS Weapons Report.



A10 Staff

|

April 2, 2026