19 June 2023

Microsoft admits early June Outlook, Azure outages caused by cyberattacks


Microsoft admits early June Outlook, Azure outages caused by cyberattacks

Microsoft has confirmed that disruption of its 365 services and Azure Cloud portal earlier this month were caused by a Layer 7 DDoS attack against the tech giant.

The company attributed the attacks to a threat actor it tracks as Storm-1359 aka Anonymous Sudan, a new pro-Kremlin hacktivist group.

The attackers are said to have launched several types of layer 7 DDoS attacks:

HTTP(S) flood attack – aims to exhaust the system resources with a high load of SSL/TLS handshakes and HTTP(S) requests processing. In this case, the attacker sends a high load (in the millions) of HTTP(S) requests that are well distributed across the globe from different source IPs. This causes the application backend to run out of compute resources (CPU and memory).

Cache bypass – attempts to bypass the CDN layer and can result in overloading the origin servers. In this case, the attacker sends a series of queries against generated URLs that force the frontend layer to forward all the requests to the origin rather than serving from cached contents.

Slowloris – this attack is where the client opens a connection to a web server, requests a resource (e.g., an image), and then fails to acknowledge the download (or accepts it slowly). This forces the web server to keep the connection open and the requested resource in memory.

According to Microsoft’s blog post, the group likely used multiple virtual private servers (VPS) together with rented cloud infrastructure, open proxies, and DDoS tools. Redmond says it has no evidence that customer data was accessed or compromised.


Back to the list

Latest Posts

Cyber Security Week in Review: November 1, 2024

Cyber Security Week in Review: November 1, 2024

In brief: Hackers are exploiting critical zero-day flaw in PTZ cameras, the Dstat.cc DDoS service disrupted by law enforcement, and more.
1 November 2024
North Korean hackers caught collaborating with Play ransomware

North Korean hackers caught collaborating with Play ransomware

The theory is that Andariel is either working as an affiliate of Play ransomware or serving as an initial access broker.
31 October 2024
Large-scale phishing campaign targeting Ukraine's taxpayers

Large-scale phishing campaign targeting Ukraine's taxpayers

The attack deploys the Litemanager RMT, which provides unauthorized access to the infected computer.
30 October 2024