Giving Service Providers Visibility Into Their Own Abuse
Cloudflare has announced a free Botnet Threat Feed aimed at service providers — including hosting providers, ISPs, and cloud compute companies. The feed delivers threat intelligence on IP addresses within a provider’s own network that have been observed participating in HTTP DDoS attacks across Cloudflare’s network. The goal: help providers identify and shut down abusive nodes, cut abuse-related operational costs, and reduce the overall volume and severity of DDoS attacks on the internet.
The service is free, part of Cloudflare’s stated mission to improve the internet’s overall safety and reliability. Providers that control their own IP space can join the early access waiting list now.
Why Cloudflare Can See What Others Can’t
Cloudflare’s visibility comes from its scale. With millions of customers — including 29% of the Fortune 1000 — and roughly 20% of all websites relying on its proxy services, the company observes a substantial portion of global DDoS traffic targeting its users.
A key technical detail makes this kind of intelligence possible: for HTTP-based DDoS attacks, the source IP addresses observed are genuine. Unlike volumetric attacks that can use spoofed addresses, an HTTP request requires a full connection between client and server, so the source must be reachable and the IP must be real. That allows Cloudflare to reliably attribute attack traffic to specific providers.
Past incidents highlight the problem. The Mantis botnet, which launched a 26 million request-per-second attack, drew a significant share of its sources from major service providers, including OVH (ASN 16276), Telkomnet (ASN 7713), iboss (ASN 137922), and Ajeel (ASN 37284). These providers are not the culprits — their infrastructure has been abused — but identifying the specific machines involved can genuinely be difficult.
In many cases, only a single IP from a given provider participates in an attack that may span thousands of bots across dozens of networks. That means the provider often sees only a tiny, decontextualized fragment of the attack traffic leaving its network, making malicious behavior nearly impossible to spot. For HTTPS-based attacks, the challenge is worse: the provider sees only encrypted traffic and has no way to distinguish between legitimate and malicious requests.
From Cloudflare’s vantage point, the complete attack surface is visible. By combining its view of the full attack with careful filtering to exclude legitimate clients, the company believes it can isolate actual attackers and help providers act.
A New Tool for an Ongoing Partnership
The feed formalizes work Cloudflare has already been doing informally since the Mantis botnet incidents. By subscribing, each provider receives a list of its own offending IPs and can take direct action against the compromised or abusive systems. The offering is intentionally free, and providers with their own IP space can sign up for early access.



