Q2 2022: The DDoS Landscape Shifts
Cloudflare's global network observed some of the largest DDoS attacks ever recorded in Q2 2022, including a 26 million request per second HTTPS attack that was automatically detected and mitigated. Beyond sheer volume, the quarter was defined by a continued cyberwar in Ukraine and Russia, and the emergence of a new wave of Ransom DDoS attacks.
Key Trends From the Quarter
War-Driven Targeting
- The conflict in Ukraine is mirrored in cyberspace, with attacks aimed at disrupting the spread of information.
- Broadcast Media companies were the most targeted industry in Ukraine. The top five most attacked industries there are all in online media, publishing, and broadcasting, accounting for nearly 80% of all DDoS attacks in the country.
- In Russia, the target profile is different. The Banking, Financial Services and Insurance (BFSI) sector was the most targeted, absorbing almost 45% of all application-layer DDoS attacks. Cryptocurrency companies were the second most attacked industry.
- Attack traffic in both countries is highly distributed, indicating the use of globally dispersed botnets.
The Rise of Ransom DDoS
- A new campaign of Ransom DDoS attacks emerged, attributed to entities claiming to be the APT group "Fancy Lazarus." This campaign has focused on financial institutions and cryptocurrency companies.
- June 2022 saw the highest peak of the year so far: one out of every five survey respondents who experienced a DDoS attack reported receiving a ransom note or threat.
- Overall, the percentage of respondents reporting ransom DDoS threats increased by 11% quarter-over-quarter.
Application-Layer Attacks
- HTTP DDoS attacks increased by 72% year-over-year.
- Organizations in the US were the most targeted, followed by Cyprus, Hong Kong, and China. Attacks on Cyprus-based organizations surged by 166% QoQ.
- The Aviation & Aerospace industry was the most targeted, with attacks increasing 493% QoQ. It was followed by the Internet industry and BFSI.
Network-Layer Attacks
- Network-layer DDoS attacks grew 109% year-over-year. Attacks larger than 100 Gbps increased by 8% QoQ, while attacks lasting longer than three hours grew by 12% QoQ.
- The Telecommunications, Gaming / Gambling, and IT services industries were the primary targets.
- Organizations in the US were the most targeted, followed by China, Singapore, and Germany.
These findings are based on attacks automatically detected and mitigated by Cloudflare's DDoS protection systems. The "DDoS activity" rate measures the percentage of attack traffic out of total traffic to normalize data and avoid biases toward locations that simply handle more traffic.
Ransom Attacks Intensify
Cloudflare surveys customers who have experienced a DDoS attack to better understand the threat landscape. For over two years, one question has asked if the attack was preceded by a threat or ransom note demanding payment to stop the assault.
The percentage of respondents reporting such threats in Q2 increased by 11% both QoQ and YoY. This quarter, mitigations have centered on attacks from the "Fancy Lazarus" campaign. The peak came in June, when one out of every five respondents reported receiving a ransom demand or threat—the highest figure since December 2021.

The percentage of respondents reporting a ransom DDoS attack or threats in advance of an attack.

HTTP Flood Analysis
Application-layer attacks, specifically HTTP DDoS attacks, aim to overwhelm a web server with more requests than it can process, causing it to drop legitimate traffic or crash entirely.

Volume by Month
While application-layer attacks were up 72% YoY, they decreased 5% QoQ. May was the busiest month in the quarter, accounting for nearly 41% of all attacks, while June saw the fewest (28%).

Top Targeted Industries
Aviation and Aerospace was the most targeted industry, with attacks soaring 493% QoQ. The Internet industry was second, followed by BFSI, with Gaming / Gambling in fourth place.

The Ukrainian and Russian Front
As the physical war continues, so does the digital one. In Ukraine, attackers appear focused on silencing information, targeting media and publishing companies above all else.

In Russia, the cyber offensive is concentrated on the financial sector. BFSI companies absorbed nearly 45% of all attacks, followed by the cryptocurrency industry, with online media in third place.

Source Countries
Source IP geolocation in HTTP attacks is reliable, as IP spoofing is not possible. A high rate of attack activity from a country indicates the presence of botnets operating within its borders.
The United States was the top source of attacks for the second straight quarter, followed by China, India, and Germany. Despite retaining the top spot, attacks from the US shrank by 48% QoQ. Meanwhile, attacks from India grew by 87%, Brazil by 67%, and Germany by 33%.

Target Countries
Attacks on US-based organizations increased by 67% QoQ, making it the top target country. Attacks on Chinese companies dropped 80% QoQ, moving China from first to fourth place. Cyprus saw a 167% surge, becoming the second most targeted country, followed by Hong Kong and the Netherlands.

Network-Layer Attack Landscape
Where application-layer attacks aim at the service users connect to, network-layer attacks target the infrastructure in between — routers, servers and the internet link itself. These use different methods, and the Q2 data shows a distinct shift in how attackers are operating.

Network-layer DDoS attacks rose 109% year-over-year and 15% quarter-over-quarter. June was the heaviest month, accounting for nearly 36% of the quarter's attacks. Volumetric attacks of 100 Gbps and above climbed 8% QoQ.

Targets and Origins
Telecommunications companies were the most targeted industry for a second straight quarter, with attacks on the sector growing 66% QoQ. Gaming came in second, followed by Information Technology and Services. The US remained the most attacked country, with attacks on US networks up 95% QoQ; China, Singapore and Germany followed.


Determining where network-layer attacks originate requires a different approach than application-layer analysis. Because no handshake is required, attackers can spoof source IP addresses freely. To account for this, Cloudflare buckets traffic by the data center where it was ingested rather than by source IP. Using this method, Palestine had the highest percentage of network-layer attack traffic, followed by Azerbaijan, South Korea and Angola.


Attack Vectors
SYN floods remained the dominant attack vector, accounting for 53% of network-layer attacks. The technique abuses the stateless initial connection request of the TCP handshake; servers have no context for these new connections, making them resource-intensive to process under flood conditions.
After SYN floods, the most frequent vectors were attacks aimed at DNS infrastructure, RST floods and generic UDP floods.

Emerging Threats
Three amplification techniques stood out as the quarter's top emerging threats. Attacks abusing the CHARGEN protocol increased 378% QoQ; Ubiquiti-based attacks rose 327% QoQ; and Memcached attacks grew 287% QoQ.

CHARGEN, defined in RFC 864 back in 1983, is a debugging service that streams arbitrary characters until the client disconnects. Attackers spoof a victim's IP and direct streams from multiple servers at the target, flooding it with responses. The Ubiquiti attack works similarly, exploiting the vendor's device discovery protocol on UDP/TCP port 10001. Memcached, a caching system that supports UDP, offers amplification factors up to 51,200x when abused the same way.
Attack Size and Duration
Attack magnitude is measured two ways: bit rate (how much traffic) and packet rate (how many packets). High bit rates clog internet links; high packet rates exhaust the processing capacity of servers and in-line appliances, forcing them to drop packets.
By packet rate
Most network-layer attacks remained below 50,000 packets per second. Though modest at Cloudflare scale, 50 kpps can still take down an unprotected property or congest a standard Gigabit Ethernet connection. Packet-intensive attacks above 50 kpps decreased in Q2, with small attacks increasing 4% as a result.


By bit rate
Most attacks stayed below 500 Mbps. Attacks in the 500 Mbps-to-100 Gbps range dropped 20-40% QoQ, while attacks above 100 Gbps grew 8%. The data suggests attackers are consolidating into more extreme volumetric events while reducing mid-range activity.


Duration
Attacks remain predominantly short-lived: 52% lasted under 10 minutes and 40% more lasted 10-20 minutes. The remaining 8% stretched from 20 minutes past three hours. Attacks lasting over three hours increased 9%.

Attacks in the 20-60 minute range increased over 15%, and those exceeding three hours rose 12%. Short attacks are particularly dangerous because they can end before manual mitigation or on-demand services can redirect traffic. Automated, always-on protection that fingerprints and blocks traffic in real time is the only practical defense against these bursts.




