Aisuru casts the longest shadow over Q3 2025

Cloudflare's 23rd quarterly DDoS report is dominated by one name: Aisuru. This botnet, estimated to control between one and four million infected hosts worldwide, was responsible for hyper-volumetric attacks that routinely exceeded 1 Tbps and 1 Bpps. In Q3 2025, the frequency of these massive attacks surged 54% quarter-over-quarter, leading to an average of 14 hyper-volumetric incidents per day.

The scale of Aisuru's operations set new records. Cloudflare mitigated a peak attack of 29.7 Tbps, a UDP carpet-bombing assault that targeted an average of 15,000 destination ports per second. A separate attack peaked at 14.1 Bpps. Both were neutralized by Cloudflare's autonomous mitigation systems, which detected and blocked the traffic without human intervention, even as the attacks randomized packet attributes to evade detection. Since the start of the year, Cloudflare has logged 2,867 Aisuru attacks, with 1,304 occurring in Q3 alone.

Aisuru's targets span telecommunications, gaming, hosting, and financial services. Its impact, however, can reach far beyond the intended victim. KrebsOnSecurity reported "widespread collateral Internet disruption" across US ISPs, caused not by a direct assault but by the sheer volume of botnet traffic routing through their networks. Portions of Aisuru are also offered for hire, letting anyone buy the capacity to cripple backbone networks for a few hundred to a few thousand dollars.

Total attack volume continues to climb. Cloudflare blocked 8.3 million DDoS attacks in Q3 2025, a 15% increase QoQ and a 40% jump year-over-year, translating to roughly 3,780 mitigated attacks per hour. The year-to-date tally of 36.2 million attacks is already 170% of the total mitigated throughout all of 2024.

The breakdown by layer shows a divergence. Network-layer attacks accounted for 71% of Q3 volume, with 5.9 million incidents, up 87% QoQ and 95% YoY. In contrast, HTTP DDoS attacks fell to 2.4 million, a 41% drop QoQ and a 17% decrease YoY.

Attackers' focus areas shifted noticeably. DDoS traffic against AI companies spiked by as much as 347% month-over-month in September, coinciding with heightened public scrutiny and regulatory review of AI. Tensions between the EU and China over rare earth minerals and EV tariffs appeared to ripple into the attack landscape. The Automotive industry rose 62 spots to become the sixth most attacked sector, while Mining, Minerals & Metals jumped 24 places to 49th. Cybersecurity firms also drew more fire, climbing 17 spots to 13th overall.

Top attacked industries

Information Technology & Services remained the most attacked industry, followed by Telecommunications and Gambling & Casinos. Media, Production & Publishing, Banking & Financial Services, Retail, and Consumer Electronics also ranked in the upper tier.

Attack characteristics and sources

Notable shifts emerged in the attack-size distribution. Incidents exceeding 100 million packets per second (Mpps) grew by 189% QoQ, while attacks surpassing 1 Tbps jumped 227% QoQ. On the HTTP layer, 4 out of every 100 attacks exceeded one million requests per second.

Brevity remains a defining trait. Most attacks end quickly: 71% of HTTP DDoS attacks and 89% of network-layer attacks conclude within ten minutes. Despite their short duration, these bursts can inflict severe operational damage, forcing engineering teams into complex recovery processes that last far longer than the attack itself.

Indonesia has now held the top spot as the world's largest DDoS source for a full year. Its rise has been dramatic; HTTP DDoS traffic originating from Indonesia has increased by 31,900% over the past five years. Seven of the top ten attack source locations are in Asia.

Geopolitics behind the targets

Attack patterns in Q3 repeatedly mirrored political unrest. The Maldives saw the sharpest climb, rising 125 spots to become the 38th most attacked country, as protests against government corruption and a controversial media bill coincided with a barrage of DDoS attacks targeting the islands.

France jumped 65 spots to 18th during the nationwide "Bloquons Tout" protest movement against austerity measures and pension reforms. Belgium rose 63 places to 74th amid large demonstrations related to Gaza. While China held on as the most attacked country, Turkey placed second and Germany third. The US leaped 11 spots to become the fifth most attacked, and the Philippines registered the largest gain within the top ten, rising 20 positions.

Vector breakdown

UDP floods, partially driven by Aisuru activity, surged 231% QoQ to become the leading network-layer vector, with attacks often randomizing packet attributes to complicate mitigation. DNS floods came in second, followed by SYN floods and ICMP floods, which together accounted for just over half of all network-layer attacks. Mirai botnet permutations, despite nearly ten years since their debut, still account for almost 2% of network-layer attacks.

At the HTTP layer, nearly 70% of attacks came from botnets already known to Cloudflare's systems, meaning protection for one customer extends to the entire network. About 20% of attacks originated from fake or headless browsers or included suspicious HTTP attributes. The remaining 10% were generic floods, unusual requests, and attacks aimed at login endpoints.

Architectural limits of traditional mitigation

On-premise appliances and on-demand scrubbing centers are struggling to cope with today's attack volume and complexity. These legacy models were built for a different threat era and are increasingly unsuited for the scale of modern botnets.

The current landscape demands a defense strategy that can absorb and neutralize attacks of unprecedented size, while remaining operationally resilient. For many organizations, a review of their existing mitigation approach against these new realities is warranted.

Cloudflare's architecture, leveraging a global network and autonomous mitigation systems, is designed to handle attacks of any scale. The company provides unmetered DDoS protection to all customers at no cost, irrespective of attack size, duration, or frequency.