CloudFare administrators report that they have detected a DDoS attack against their infrastructure and that it involves an advertising network as well as unsuspecting users who are being tricked into participating in the attack by malicious ads.

The attack only lasted a few hours, but managed to reach a volume of nearly 275,000 HTTP requests per second. The company also says that they successfully mitigated the attack without having to take down their servers.
As CloudFare reports, they speculate that this was a new type of DDoS attack, which uses advertising networks and unsuspecting users.
The attack is channeled by real traffic and real people
According to the company's researchers, they suspect that a random web browsing session by users on their computer or mobile phone served them an iframe containing an advertisement.
The iframe requested the content of an ad from the advertising network, which in turn requested the content of said ad from the servers of the person distributing that particular ad.
Unknown to the user and the advertising network, the ad distributor (i.e. the attacker) serves a malicious ad, which contains JavaScript code and aims to make a request to the victim (which in this case was a website hosted on the CloudFare infrastructure).
The attack came from China
The attack was very innovative in its approach, and according to CloudFare, it does not involve a TCP packet like classic DDoS attacks, but looks like real everyday traffic.
After analyzing millions of log lines, CloudFare says that 99.8% of the traffic came from Chinese IP addresses. The attackers likely originated from the same country, mainly due to the comments left in the malicious JavaScript code, which were also in Chinese.
72% of the users who intervened in the DDoS attack used a mobile device, 23% used a desktop browser, while 5% of the users were tablet users.
