The multi-terabit era of distributed denial-of-service (DDoS) attacks is no longer an anomaly; it is the new baseline. During the third quarter of 2022, Cloudflare's autonomous systems detected and mitigated numerous attacks exceeding 1 Tbps. The most significant was a 2.5 Tbps flood targeting Wynncraft, a massively multiplayer online Minecraft server protected by Cloudflare Spectrum. This attack, launched by a Mirai botnet variant, was the largest ever recorded by bitrate, consisting of a mix of UDP and TCP floods. Despite the massive volume, the server remained online and unaffected as the malicious traffic was filtered at the edge.








L3/4 attack volume climbs again
Attacks that target network infrastructure directly — layer 3/4 (L3/4) — aim to overwhelm in-line routers, servers, and the internet link itself, rather than the application layer that end users interact with. After three consecutive quarters of growth, the volume of these attacks rose 97% year-over-year and 24% quarter-over-quarter in Q3.

The distribution of attack traffic was relatively even across the quarter, with July taking a slightly larger share.

Which industries and countries took the brunt
The Gaming and Gambling industry was the most targeted sector for L3/4 attacks. Nearly one in five bytes Cloudflare ingested toward Gaming and Gambling networks was part of a DDoS attack — a 381% increase quarter-over-quarter. Telecommunications, which led in Q2, fell to second place with a 58% drop in attack traffic but still saw almost 6% of bytes toward its networks tied to attacks. Information Technology and Services and Software also saw meaningful increases of 89% and 150% quarter-over-quarter respectively.

By target country, Singapore was the most attacked, with over 15% of all bytes destined for its networks associated with DDoS activity — a 1,175% quarter-over-quarter jump. US-based targets ranked second after a 45% quarterly decrease, while China and Taiwan both saw increases of 62% and 200% quarter-over-quarter, respectively.

On the ingress side, Cloudflare data centers located in Azerbaijan handled the highest percentage of attack traffic: more than a third of all packets ingested there were part of an L3/4 attack — up 44% quarter-over-quarter and a massive 59-fold year-over-year. Tunisia saw a 173-fold jump compared to the prior year, and significant increases were also observed in Zimbabwe and Germany.
In East Asia, Cloudflare data centers in Taiwan and Japan both saw sharp rises in attack packets — 207% and 278% quarter-over-quarter, and 1,989% and 1,921% year-over-year, respectively. Conversely, attack traffic in Ukraine- and Russia-based data centers declined by 49% and 16% quarter-over-quarter.

Attack vectors and emerging threats
SYN floods and DNS attacks accounted for a combined 71% of all L3/4 attacks, remaining the dominant methods for launching DDoS campaigns.

Several attack types that resurfaced in the previous quarter—abuse of the CHARGEN protocol, the Ubiquity Discovery Protocol, and Memcached reflection attacks—continued to appear. While Memcached misuse grew by 48%, more notable were spikes in attacks abusing the BitTorrent protocol, up 1,221% quarter-over-quarter, and those launched by the Mirai botnet and its variants, which rose 405%.
BitTorrent amplification: BitTorrent is a peer-to-peer file-sharing protocol. Clients use trackers and distributed hash tables to identify seeders hosting files. Attackers can spoof a victim's IP address as a seeder within these systems; the resulting flood of file requests can overwhelm the victim with traffic.
Mirai botnet: Mirai is malware that targets smart devices running on ARC processors with a stripped-down Linux OS. If default credentials remain unchanged, Mirai logs in and infects the device, adding it to a botnet that operators can command to flood victims with UDP packets.

Attack size and duration
While terabit-scale attacks are making headlines, they remain outliers. Over 95% of attacks peaked below 50,000 packets per second, and more than 97% were below 500 Mbps. Most of the traffic can be classified as "cyber vandalism": attacks launched with readily available tools and open-source botnet code, typically aimed at a school, a small business, or a personal website. These opportunistic attacks are distinct from the larger, more sophisticated campaigns staged by organized crime or state-level actors.

Most attacks also continue to be brief: 94% finished within 20 minutes. While there was a 9% quarter-over-quarter increase in attacks lasting one to three hours and a 3% increase in those exceeding three hours, lengthy campaigns remain the exception.

Even the largest attacks were short-lived. The 2.5 Tbps attack Cloudflare mitigated lasted about two minutes; the 26 million request-per-second attack peaked for just 15 seconds. These durations underline the need for automated, always-on mitigation: by the time a human responder could react to a notification, the attack would already be over.
Automation is the only defense that scales
DDoS attacks are executed by bots, so defending against them must be equally automated. Manual response cannot keep pace with attacks that peak and subside in minutes or seconds. Cloudflare continues to provide unmetered and unlimited DDoS protection free of charge to all customers, a stance it first pioneered in 2017. The full report is available as a PDF.



