Millions of Malicious Requests Flood Servers: A Botnet DDoS Attack

2025-04-02

A recent surge in abusive web crawlers has overwhelmed servers with millions of requests. The attack originates from numerous IP addresses, each making a small number of requests with disguised user agents, making detection and blocking difficult. One shared hosting server alone averages over 1.5 million fraudulent requests daily from 290,000 unique IPs. Analysis suggests a botnet of compromised Android set-top boxes is likely responsible, aiming to evade anti-crawler measures. This incident has wasted significant staff time and impacted some legitimate users.