Cloudflare DDoS threat report 2022 Q3 The multi-terabit era of distributed denial-of-service (DDoS) attacks is no longer an anomaly; it is the new baseline. During the third quarter of 2022, Cloudflare's autonomous systems detected and mitigated numerous attacks exceeding 1 Tbps. The most significant was a 2.5 Tbps flood targeting Wynncraft, a massively multiplayer online Minecraft server protected by Cloudflare Spectrum. This attack, launched by a Mirai botnet variant, was the largest ever recorded by bitrate, consisting of a mix of UDP and TCP floods. Despite the massive volume, the server remained online and unaffected as the malicious traffic was filtered at the edge.
A graph of the 2.5 Tbps DDoS attack that targeted Wynncraft
## Key Trends and Shifts The overall threat landscape this quarter shows a continued escalation. Year-over-year, the total volume of DDoS attacks increased, with a particular surge in volumetric attacks that lasted longer than in previous periods. There was a distinct spike in activity from the Mirai botnet and its many variants. Geographically, the data reveals significant surges in attacks targeting networks and services in Taiwan and Japan. Alongside the rise in raw attack volume, the report notes a separate increase in the frequency of extortion campaigns. These Ransom DDoS attacks, where attackers demand payment to halt or prevent an attack, were reported by 15% of surveyed customers, marking a 67% increase year-over-year and a 15% increase quarter-over-quarter. ## Network-Layer Attacks Attacks at the network layer (L3/4) increased by an alarming 97% year-over-year and 24% quarter-over-quarter. The primary driver of this growth was an explosion in Mirai-related botnet activity, which saw a 405% increase in L3/4 attacks compared to the previous quarter. The industry absorbing the brunt of this traffic was Gaming and Gambling, which became the most targeted sector and was the subject of the record-breaking 2.5 Tbps attack. A closer look at the monthly distribution of these attacks shows a significant peak in September, with almost a quarter of customers reporting a related threat that month—the highest monthly figure of the year.
Graph of Ransom DDoS attacks by quarter
### Methodology Cloudflare's autonomous systems analyze all incoming traffic and automatically apply mitigation measures. After an attack is mitigated, customers are prompted to complete a survey to provide details about the event. To calculate these trends, Cloudflare reviewed the responses to this survey, collecting an average of 174 responses per quarter over the past year. One question specifically asks whether the attack was accompanied by a ransom demand or threat.
Graph of Ransom DDoS attacks by month
## Application-Layer Attacks Focusing on HTTP DDoS attacks reveals a mixed picture. While attacks decreased by approximately 8% each quarter since the start of 2022, the year-over-year comparison still shows an enormous increase of 111%. Within Q3, the volume was relatively balanced, with September accounting for 36% of the quarter's attacks and July the lowest at 29%.
Graph of HTTP DDoS attacks by quarter
Graph of HTTP DDoS attacks by month in 2022 Q3
### Most-Targeted Sectors and Geographies When analyzed by industry, Internet companies were the primary targets, with attacks rising 131% from the prior quarter and 300% year-over-year. They were followed by the Telecommunications sector, which saw a 93% surge quarter-over-quarter. The Gaming and Gambling industry, which was the top target for L3/4 attacks, was third for HTTP attacks.
Graph of the top industries targeted by HTTP DDoS attacks in 2022 Q3
A look at attack targets by customer billing country places US-based operations at the top, seeing a 60% increase in attacks quarter-over-quarter, with China as the second most targeted. Notably, attacks against Taiwanese companies surged by 200% from the previous quarter, and those targeting Japanese companies rose by 105%.
Graph of the top countries targeted by HTTP DDoS attacks in 2022 Q3
The shift in targeted industries within specific nations offers insight into geopolitical events. During the prior two quarters, Ukrainian media and publishing companies were the primary targets. However, in Q3, they dropped off the top ten list entirely. Instead, the Marketing & Advertising industry was the most targeted in Ukraine, comprising 40% of attacks. In Russia, attacks on the Banking, Financial Services, and Insurance (BFSI) sector persisted and remained the most common, despite a 44% decrease from the prior quarter. In Taiwan, online media bore the brunt, with over half of the attacks on the country targeting that sector. Similarly, in Japan, internet and media companies were the primary victims, receiving 52% of the attack traffic. ### Source of Attack Traffic It is important to note that attributing attack traffic to a specific country does not necessarily identify the attacker's physical location, but rather the location of the botnet infrastructure. After two consecutive quarters in the lead, the US was replaced by China as the largest source of HTTP DDoS attack traffic in Q3, with a 19% increase in traffic originating from Chinese IP addresses. India moved into second place, displacing other nations. In a move that reflects the current conflict, attack traffic originating from within Ukraine and Russia dropped by 29% and 11% respectively, compared to the previous quarter. Meanwhile, traffic from Japanese IPs saw a sharp 130% increase compared to the same time last year.
Graph of the top source countries of HTTP DDoS attacks in 2022 Q3

L3/4 attack volume climbs again

Attacks that target network infrastructure directly — layer 3/4 (L3/4) — aim to overwhelm in-line routers, servers, and the internet link itself, rather than the application layer that end users interact with. After three consecutive quarters of growth, the volume of these attacks rose 97% year-over-year and 24% quarter-over-quarter in Q3.

Graph of L3/4 DDoS attacks by quarter

The distribution of attack traffic was relatively even across the quarter, with July taking a slightly larger share.

Graph of L3/4 DDoS attacks by month in 2022 Q3

Which industries and countries took the brunt

The Gaming and Gambling industry was the most targeted sector for L3/4 attacks. Nearly one in five bytes Cloudflare ingested toward Gaming and Gambling networks was part of a DDoS attack — a 381% increase quarter-over-quarter. Telecommunications, which led in Q2, fell to second place with a 58% drop in attack traffic but still saw almost 6% of bytes toward its networks tied to attacks. Information Technology and Services and Software also saw meaningful increases of 89% and 150% quarter-over-quarter respectively.

Graph of the top industries targeted by L3/4 DDoS attacks in 2022 Q3

By target country, Singapore was the most attacked, with over 15% of all bytes destined for its networks associated with DDoS activity — a 1,175% quarter-over-quarter jump. US-based targets ranked second after a 45% quarterly decrease, while China and Taiwan both saw increases of 62% and 200% quarter-over-quarter, respectively.

Graph of the top countries targeted by L3/4 DDoS attacks in 2022 Q3

On the ingress side, Cloudflare data centers located in Azerbaijan handled the highest percentage of attack traffic: more than a third of all packets ingested there were part of an L3/4 attack — up 44% quarter-over-quarter and a massive 59-fold year-over-year. Tunisia saw a 173-fold jump compared to the prior year, and significant increases were also observed in Zimbabwe and Germany.

In East Asia, Cloudflare data centers in Taiwan and Japan both saw sharp rises in attack packets — 207% and 278% quarter-over-quarter, and 1,989% and 1,921% year-over-year, respectively. Conversely, attack traffic in Ukraine- and Russia-based data centers declined by 49% and 16% quarter-over-quarter.

A graph of top Cloudflare data center locations with the highest percentage of DDoS attack traffic in 2022 Q3

Attack vectors and emerging threats

SYN floods and DNS attacks accounted for a combined 71% of all L3/4 attacks, remaining the dominant methods for launching DDoS campaigns.

A graph of the top attacks vectors in 2022 Q3

Several attack types that resurfaced in the previous quarter—abuse of the CHARGEN protocol, the Ubiquity Discovery Protocol, and Memcached reflection attacks—continued to appear. While Memcached misuse grew by 48%, more notable were spikes in attacks abusing the BitTorrent protocol, up 1,221% quarter-over-quarter, and those launched by the Mirai botnet and its variants, which rose 405%.

BitTorrent amplification: BitTorrent is a peer-to-peer file-sharing protocol. Clients use trackers and distributed hash tables to identify seeders hosting files. Attackers can spoof a victim's IP address as a seeder within these systems; the resulting flood of file requests can overwhelm the victim with traffic.

Mirai botnet: Mirai is malware that targets smart devices running on ARC processors with a stripped-down Linux OS. If default credentials remain unchanged, Mirai logs in and infects the device, adding it to a botnet that operators can command to flood victims with UDP packets.

A graph of the top emerging threats in 2022 Q3

Attack size and duration

While terabit-scale attacks are making headlines, they remain outliers. Over 95% of attacks peaked below 50,000 packets per second, and more than 97% were below 500 Mbps. Most of the traffic can be classified as "cyber vandalism": attacks launched with readily available tools and open-source botnet code, typically aimed at a school, a small business, or a personal website. These opportunistic attacks are distinct from the larger, more sophisticated campaigns staged by organized crime or state-level actors.

A graph of the distribution of DDoS attacks by bitrate in 2022 Q3

Most attacks also continue to be brief: 94% finished within 20 minutes. While there was a 9% quarter-over-quarter increase in attacks lasting one to three hours and a 3% increase in those exceeding three hours, lengthy campaigns remain the exception.

A graph of the QoQ change in the duration of DDoS attacks in 2022 Q3

Even the largest attacks were short-lived. The 2.5 Tbps attack Cloudflare mitigated lasted about two minutes; the 26 million request-per-second attack peaked for just 15 seconds. These durations underline the need for automated, always-on mitigation: by the time a human responder could react to a notification, the attack would already be over.

Automation is the only defense that scales

DDoS attacks are executed by bots, so defending against them must be equally automated. Manual response cannot keep pace with attacks that peak and subside in minutes or seconds. Cloudflare continues to provide unmetered and unlimited DDoS protection free of charge to all customers, a stance it first pioneered in 2017. The full report is available as a PDF.