The attack originated and was used on Chinese mobile users
CloudFare administrators reported a DDoS detected against their infrastructure involving an advertising network and unsuspecting users visiting websites randomly displaying malicious ads.
The attack only lasted a few hours, but it managed to reach a peak volume of 275,000 HTTP requests per second. The company also says it successfully mitigated the attack without any downtime.
As CloudFare reports, it is speculated that this was a new type of DDoS, using advertising networks and unsuspecting users.
The attack was channeling real traffic from real people
According to the company's researchers, they suspect that random users were browsing the Web from their computer or mobile browser and were presented with an iframe that contained an advertisement.
The iframe requested ad content from the ad network, which in turn requested ad content from the servers of the person who won the particular ad placement bid.
Unknown to the user and the advertising network, the winner of the bid (attacker) displayed a malicious ad, which contained JavaScript that sent an XHR (Ajax) request to the victim (in this case, a website hosted on CloudFare infrastructure).
The DDoS attack originated from China
The attack was very innovative in its approach, and according to CloudFare it did not involve a TCP packet, resembling real day-to-day traffic.
After analyzing millions of log lines, CloudFare says that 99.8% of the traffic came from Chinese IP addresses. The attackers also likely came from the same country, largely due to the comments left in the malicious JavaScript code, which were also in Chinese.
72% of users were using a mobile device, 23% a desktop browser, while 5% of users were browsing the web from tablet . Additionally, much of the user data contained also showed that traffic came from mobile apps, not necessarily web browsers.

