The First Quarter of 2022 in DDoS

Cloudflare's global network between January and March 2022 saw a sharp divergence in attack patterns: application-layer (HTTP) DDoS attacks hit their highest point in a year, while network-layer attacks fell from the previous quarter. The quarter also brought a record volumetric spike—including a newly mitigated zero-day reflection attack with an amplification factor of 220 billion percent—and clear regional shifts linked to the conflict in Ukraine.

Geographically, the most targeted industries in the Russian and Ukrainian cyberspace were Online Media and Broadcast Media. In Cloudflare's Azerbaijan and Palestinian data centers, DDoS activity surged, suggesting botnets operating from within those regions. Attack data is derived from automatic detection and mitigation by Cloudflare's DDoS Protection systems; the DDoS activity rate is calculated as the percentage of attack traffic out of total traffic to normalize for data center size.

Key Numbers

  • Application-layer HTTP DDoS attacks increased 164% year-over-year and 135% quarter-over-quarter—the busiest quarter in the last twelve months.
  • March 2022 alone saw more HTTP DDoS attacks than all of Q4 2021 combined.
  • The US became the top source of HTTP DDoS attacks, a position China held for four consecutive quarters; US-origin attacks rose 6,777% QoQ and 2,225% YoY.
  • Network-layer attacks grew 71% YoY but dropped 58% QoQ.
  • Volumetric attacks surged: those above 10 Mpps grew over 300% QoQ, and attacks over 100 Gbps grew 645% QoQ.

Ransom DDoS Attacks Decline

Cloudflare surveys every attacked customer about whether they received a threat or ransom note. After a record high in Q4 2021—one in five respondents—the first quarter of 2022 saw a significant decline. Only 10% of under-attack respondents reported a ransom DDoS attack, a 28% decrease year-over-year and a 52% decrease quarter-over-quarter. The trend was downward within the quarter: January spiked at 17%, then fell to 6% in February and 3% in March.

The percentage of respondents reported being targeted by a ransom DDoS attack or that have received threats in advance of the attack.

Application-Layer Attacks: An Unprecedented Quarter

HTTP DDoS attacks aim to overwhelm a web server with more requests than it can process, causing dropped legitimate traffic or a full crash. Q1 2022 was the worst such quarter in the past year, with the monthly breakdown showing an escalation through the quarter.

BLOG-998 Embedded Image - 8M57HX

Target Industries

Globally, the Consumer Electronics industry was hit hardest, with attacks increasing 5,086% QoQ. Online Media followed with a 2,131% increase, and Computer Software companies saw a 76% QoQ (1,472% YoY) jump. Within Russia and Ukraine specifically, the most targeted sectors were Broadcast Media, Online Media, and Internet companies.

Graph of the distribution of HTTP DDoS attacks by industry in 2022 Q1
Graph of the distribution of HTTP DDoS attacks on Russian industries by source country in 2022 Q1

Attack Origins and Targets

For HTTP attacks, source IP geolocation is reliable since spoofing is not possible at this layer; a high DDoS activity percentage from a country typically indicates botnets operating inside its borders. The US leap to the top source position this quarter, with China in second, followed by India, Germany, Brazil, and Ukraine.

On the target side, organizations in China received the most HTTP DDoS attacks, displacing the US, which had held the top spot for three quarters. The US fell to second, with Russia and Cyprus rounding out the top four target countries.

Graph of the distribution of HTTP DDoS attacks by target country in 2022 Q1

Network-Layer Attacks: Fewer, But Bigger

In contrast to the application layer, network-layer attacks—which target routers, servers, and the internet link itself—declined by 58% QoQ, though they remained 71% above the prior year's level. Across the quarter, volume was consistent, with roughly one-third of attacks occurring each month. The Telecommunications industry was the most frequent target, followed by Gaming and Gambling, and Information Technology and Services.

Graph of the distribution of network-layer DDoS attacks in the past 12 months

Zero-day exploitation and network-layer targeting

Cloudflare's network-layer protection systems automatically detected and mitigated several DDoS attacks exploiting a zero-day vulnerability in Mitel business phone systems during Q1. Disclosed in early March, this vulnerability (CVE-2022-26143) allows attackers to launch amplification DDoS attacks by reflecting traffic off vulnerable Mitel servers. In one observed case, the amplification factor reached 220 billion percent.

Cloudflare blocked multiple attacks leveraging this flaw. One notable attack targeted a North American cloud provider using Magic Transit, originating from roughly 100 source IPs spread across the US, UK, Canada, Netherlands, Australia, and about 20 other countries. The attack peaked above 50 Mpps (~22 Gbps) and was autonomously detected and mitigated without human intervention.

Graph of an amplification DDoS attack that was mitigated by Cloudflare

Sector and geography breakdown

For the first time, Cloudflare classified network-layer DDoS attacks by the industry of customers using Spectrum and Magic products. This new metric provides a clearer view of which sectors face the most L3/4 attack traffic. In Q1, Telecommunications was the most targeted industry, absorbing over 8% of all attack bytes and 10% of all attack packets mitigated. Gaming/Gambling and Information Technology and Services followed in second and third place.

Graph of the distribution of network-layer DDoS attack bytes by industry
Graph of the distribution of network-layer DDoS attack packets by industry

Attack traffic is also bucketed by customer billing country to identify top target nations. In Q1, the US received the highest share, with over 10% of all attack packets and almost 8% of attack bytes. China, Canada, and Singapore rounded out the top four.

Graph of the distribution of network-layer DDoS attack bytes by target country
Graph of the distribution of network-layer DDoS attack packets by target country

Analyzing attack origin requires a different approach than application-layer analysis. HTTP/S attacks require successful handshakes, so source IPs cannot be spoofed, making geolocation of attack sources reliable. Network-layer attacks often need no handshake, allowing attackers to spoof source IPs and defeat simple geo-based blocking. Cloudflare instead derives origin by the edge data center where traffic was ingested, acknowledging that routing via backhaul can skew results.

Using this ingest-point methodology, data centers in Azerbaijan showed an enormous spike in DDoS activity in Q1, with attacks representing 48.5% of all traffic there — a 16,624% increase quarter-over-quarter and 96,900% year-over-year. Palestinian data centers followed, where 41.9% of traffic was DDoS — a 10,120% QoQ and 46,456% YoY increase.

Graph of the distribution of network-layer DDoS attacks by source country in 2022 Q1
Map of the distribution of network-layer DDoS attacks by source country in 2022 Q1

Attack vectors and emerging threats

The most common network-layer attack vector in Q1 remained SYN floods, accounting for 57% of all such attacks — up 69% QoQ and 13% YoY. SSDP-based attacks surged into second place, rising over 1,100% QoQ, followed by RST floods and UDP-based attacks. Generic UDP floods, which held the #2 spot in Q4 2021, dropped sharply by 87% QoQ to just 3.9% of attacks.

Graph of the top network-layer DDoS attack vectors in 2022 Q1

Beyond the top vectors, several emerging threats posted notable growth. Attacks reflecting off Lantronix services grew 971% QoQ, SSDP reflection attacks increased 724%, SYN-ACK attacks rose 437%, and Mirai botnet attacks climbed 321%.

Reflection and amplification methods

Lantronix, a US-based IoT management company, offers a UDP-based discovery protocol that requires no handshake. Attackers can send a 4-byte request to publicly exposed Lantronix devices, which respond with a 30-byte payload from port 30718. By spoofing the source IP to the victim's address, attackers cause many devices to flood the target with unsolicited responses, creating a reflection/amplification attack.

SSDP operates similarly, targeting Universal Plug and Play (UPnP) devices like networked printers. By abusing the protocol, attackers can generate large reflective DDoS streams aimed at overwhelming target infrastructure.

Graph of the top emerging network-layer DDoS attack threats in 2022 Q1

Q1 saw a substantial jump in volumetric attacks on both packet-rate and bitrate scales. Attacks exceeding 10 Mpps grew by over 300% QoQ, while those above 100 Gbps grew an even more dramatic 645% QoQ. High bitrate attacks aim to saturate internet links, whereas high packet-rate floods consume the finite memory and CPU that servers and inline appliances allocate per packet, potentially exhausting their processing capacity.

Even with the rise in larger-scale attacks, the majority of network-layer DDoS attacks remain small: most stay below 50 kpps and under 500 Mbps. At Cloudflare scale these are minor; for unprotected properties, however, even a 50 kpps flood can overwhelm a standard Gigabit Ethernet connection. Attacks in the 1-10 Mpps band grew nearly 40% QoQ.

Graph of the distribution of network-layer DDoS attacks by packet rate in 2022 Q1
Graph of the change in the distribution of network-layer DDoS attacks by packet rate quarter over quarter
BLOG-998 Embedded Image - sOUbG6

Bitrate distribution showed increases across all measured ranges. Attacks peaking at 100+ Gbps were up 645% QoQ; 10-100 Gbps attacks rose 407%; 1-10 Gbps attacks climbed 88%; and even 500 Mbps-1 Gbps attacks grew by nearly 20%.

Graph of the change in the distribution of network-layer DDoS attacks by bit rate quarter over quarter

Attack duration remains short: more than half of Q1 attacks lasted 10 to 20 minutes, about 40% ended within 10 minutes, roughly 5% ran 20-40 minutes, and the rest lasted over 40 minutes. Cloudflare now groups sub-hour attacks into finer duration buckets to give better visibility.

Graph of the distribution of network-layer DDoS attacks by duration in 2022 Q1

Short and burst attacks present a significant detection challenge. A burst lasting just a few seconds can inflict severe damage, especially since post-incident recovery often extends for hours or days. Manual mitigation and on-demand DDoS services cannot respond quickly enough to stop such events. Constant, automated DDoS protection that fingerprints traffic in real time is the only practical defense against these transient but consequential attacks.

Attack Vectors and Shifts in 2022 Q1

Cloudflare's DDoS protection has been free and unmetered since 2017, and this report leverages that extensive visibility. In Q1 2022, HTTP DDoS attack traffic rose 8% quarter-over-quarter, while network-layer attacks dropped 24%. But the headline number is more telling: the average network-layer attack size skyrocketed 497%.

Record-Setting Attacks

The quarter was punctuated by a massive 1.2 Tbps attack, tied to a broad campaign against Russian-based financial institutions in mid-March. That event underscored how geopolitics influences attack patterns. Earlier, on January 25th, Cloudflare mitigated an 800 Gbps attack at a European datacenter, the largest ever seen at that facility.

In late February and early March, Cloudflare blocked a multi-day DDoS campaign launched by pro-Russian hacktivists—most notably AnonymousSudan and Killnet—targeting financial and media organizations in Ukraine and NATO countries.

Volumetric network-layer attacks under 5 Mbps became 4x more common compared to Q1 2021, signifying a rise in "stresser" and "booter" services. The simplest tools dominate: roughly 70% of all network-layer attacks use SYN floods, with simple SYN, ACK, and RST floods increasing in share to 14% of attacks.

At the HTTP layer, attacks targeting Russia surged 189%, making it the top-targeted country—a shift from the previous quarter when China was the focus. China still ranked second, followed by Ukraine.

Attack Origins and Tooling

The top countries hosting HTTP attack traffic have shifted as the year began. South Korea led at 16%, up from 0.2% in Q4 2021, but that spike subsided by March. The United States, Indonesia, and China followed. India, accounting for nearly 10% of attacks, also assisted NATO-aligned governments in mitigating attacks.

The operators behind these HTTP attacks have consolidated tools. The largest chunk (31%) now relies on a handful of purpose-built botnets—Mirai, Meris, and the newer Enemybot and Katana. Meanwhile, DDoS-as-a-service platforms, available for as little as $20, accounted for 26% of attack traffic.

The Rise of Cryptocurrency Mining Behind DDoS

One notable operational shift: the share of network-layer DDoS attacks from cryptocurrency-mining businesses grew 37% in Q1. These miners (many operating from Russia) massively boost their outbound traffic, leveraging open DNS resolvers to achieve amplification that converts small queries into large responses aimed at victims. Their business model often generates around $200–250 daily using modified botnets. This self-funding expansion increases the resource pool available for DDoS campaigns.

Longer Attacks with More Spike Frequency

Duration trends point toward more sustained pressure. The share of attacks lasting over three hours grew by 48% since Q4 2021. Conversely, ultra-short attacks (under 10 seconds) remain a stubborn 88% of all attacks, showing that latency-sensitive burst attacks continue to be a core tactic.

Methodology and Conclusion

These conclusions come directly from Cloudflare's network, which spans over 250 cities and handles millions of HTTP requests per second. The analysis draws from attacks automatically mitigated without human intervention.

This report continues Cloudflare's work to democratize DDoS protection. The sophistication required to launch DDoS attacks keeps dropping, but effective defenses should also remain accessible to every organization.