
"To generate these garbage requests, bad guys use 'botnets' made up of computers of unsuspecting users which were infected with malware at some point in the past. This makes a DDoS similar to the zombie apocalypse: one of the whopper lemmings just might be your grandpa."
But, "There’s a bright side: All of these lemmings are there just to overload the servers with extra work – they can’t take away your BigMac and coke. Your data is safe."“Telegram CEO Pavel Durov isn't crazy for suspecting the Chinese government is targeting Telegram," said Paul Bischoff, privacy advocate at Comparitech.com, in emailed comments. "It wouldn't be the first time that China has weaponized botnets... to target websites with DDoS attacks," he added, referring to a wave of attacks against GitHub in 2015 that experts say targeted pages containing content or links to content that was banned in China.
Bischoff said Telegram users who are unable to access the service should "try using a VPN to connect to a few different countries so that your connection to Telegram goes through a server that's not under attack. Some VPNs even enable you to use Telegram from within mainland China, where it is normally censored.""This type of attack is government censorship using cyber tools to block internet traffic," said Mark Skilton, professor of practice at Warwick Business School. "This was not a specific technology, but a distributed network attack on the internet ISP and NSP network providers. The strong encryption inside the Telegram app had no defense against the traffic level protocols and volume of traffic."To stop this type of attack would need new technology to block adversaries' traffic before the network, something that is not possible if the Chinese government control and have access to that network currently. What typically happens is alternative telecoms networks might be used. But I suspect those too would be targeted for a full-scale attack," continued Skilton, who researches and consults on cybersecurity. "However, we don't know if it was a full wide-scale internet attack or if it was a complete network-wide attack. It seems some sophistication was used to target the Telegram app and user service. This may be a symptom of a more advanced distributed 'denial of service' acting as a swarm of attacks against specific targets."