
11/9/2021 · Vivek Ganti, Omer Yoachimik
What this post added
This post details the analysis of the Meris botnet, a significant threat that exploits MikroTik router vulnerabilities (CVE-2018-14847) to launch large-scale DDoS attacks. It describes the botnet's characteristics, attack vectors (HTTP pipelining, SOCKS proxies), targets (industries and countries), and compares it to the Mirai botnet. Cloudflare's existing DDoS protection systems automatically detect and mitigate these attacks, with additional rules deployed for more comprehensive mitigation and threat intelligence gathering. The post also highlights the use of Cloudflare Radar for visualizing attack data.