Q2 2022: The DDoS Landscape Shifts

Cloudflare's global network observed some of the largest DDoS attacks ever recorded in Q2 2022, including a 26 million request per second HTTPS attack that was automatically detected and mitigated. Beyond sheer volume, the quarter was defined by a continued cyberwar in Ukraine and Russia, and the emergence of a new wave of Ransom DDoS attacks.

DDoS attack trends for 2022 Q2

War-Driven Targeting

  • The conflict in Ukraine is mirrored in cyberspace, with attacks aimed at disrupting the spread of information.
  • Broadcast Media companies were the most targeted industry in Ukraine. The top five most attacked industries there are all in online media, publishing, and broadcasting, accounting for nearly 80% of all DDoS attacks in the country.
  • In Russia, the target profile is different. The Banking, Financial Services and Insurance (BFSI) sector was the most targeted, absorbing almost 45% of all application-layer DDoS attacks. Cryptocurrency companies were the second most attacked industry.
  • Attack traffic in both countries is highly distributed, indicating the use of globally dispersed botnets.

The Rise of Ransom DDoS

  • A new campaign of Ransom DDoS attacks emerged, attributed to entities claiming to be the APT group "Fancy Lazarus." This campaign has focused on financial institutions and cryptocurrency companies.
  • June 2022 saw the highest peak of the year so far: one out of every five survey respondents who experienced a DDoS attack reported receiving a ransom note or threat.
  • Overall, the percentage of respondents reporting ransom DDoS threats increased by 11% quarter-over-quarter.

Application-Layer Attacks

  • HTTP DDoS attacks increased by 72% year-over-year.
  • Organizations in the US were the most targeted, followed by Cyprus, Hong Kong, and China. Attacks on Cyprus-based organizations surged by 166% QoQ.
  • The Aviation & Aerospace industry was the most targeted, with attacks increasing 493% QoQ. It was followed by the Internet industry and BFSI.

Network-Layer Attacks

  • Network-layer DDoS attacks grew 109% year-over-year. Attacks larger than 100 Gbps increased by 8% QoQ, while attacks lasting longer than three hours grew by 12% QoQ.
  • The Telecommunications, Gaming / Gambling, and IT services industries were the primary targets.
  • Organizations in the US were the most targeted, followed by China, Singapore, and Germany.

These findings are based on attacks automatically detected and mitigated by Cloudflare's DDoS protection systems. The "DDoS activity" rate measures the percentage of attack traffic out of total traffic to normalize data and avoid biases toward locations that simply handle more traffic.

Ransom Attacks Intensify

Cloudflare surveys customers who have experienced a DDoS attack to better understand the threat landscape. For over two years, one question has asked if the attack was preceded by a threat or ransom note demanding payment to stop the assault.

The percentage of respondents reporting such threats in Q2 increased by 11% both QoQ and YoY. This quarter, mitigations have centered on attacks from the "Fancy Lazarus" campaign. The peak came in June, when one out of every five respondents reported receiving a ransom demand or threat—the highest figure since December 2021.

Graph of ransom DDoS attacks by quarter

The percentage of respondents reporting a ransom DDoS attack or threats in advance of an attack.

Graph of ransom DDoS attacks by month

HTTP Flood Analysis

Application-layer attacks, specifically HTTP DDoS attacks, aim to overwhelm a web server with more requests than it can process, causing it to drop legitimate traffic or crash entirely.

A diagram of a DDoS attack denying service to legitimate users

Volume by Month

While application-layer attacks were up 72% YoY, they decreased 5% QoQ. May was the busiest month in the quarter, accounting for nearly 41% of all attacks, while June saw the fewest (28%).

Graph of the yearly distribution of application-layer DDoS attacks by month in the past 12 months

Top Targeted Industries

Aviation and Aerospace was the most targeted industry, with attacks soaring 493% QoQ. The Internet industry was second, followed by BFSI, with Gaming / Gambling in fourth place.

Graph of the distribution of HTTP DDoS attacks by industry in 2022 Q2

The Ukrainian and Russian Front

As the physical war continues, so does the digital one. In Ukraine, attackers appear focused on silencing information, targeting media and publishing companies above all else.

Graph of the distribution of HTTP DDoS attacks on Ukrainian industries by source country in 2022 Q2

In Russia, the cyber offensive is concentrated on the financial sector. BFSI companies absorbed nearly 45% of all attacks, followed by the cryptocurrency industry, with online media in third place.

Graph of the distribution of HTTP DDoS attacks on Russian industries by source country in 2022 Q2

Source Countries

Source IP geolocation in HTTP attacks is reliable, as IP spoofing is not possible. A high rate of attack activity from a country indicates the presence of botnets operating within its borders.

The United States was the top source of attacks for the second straight quarter, followed by China, India, and Germany. Despite retaining the top spot, attacks from the US shrank by 48% QoQ. Meanwhile, attacks from India grew by 87%, Brazil by 67%, and Germany by 33%.

Graph of the distribution of HTTP DDoS attacks by source country in 2022 Q2

Target Countries

Attacks on US-based organizations increased by 67% QoQ, making it the top target country. Attacks on Chinese companies dropped 80% QoQ, moving China from first to fourth place. Cyprus saw a 167% surge, becoming the second most targeted country, followed by Hong Kong and the Netherlands.

Graph of the distribution of HTTP DDoS attacks by target country in 2022 Q2

Network-Layer Attack Landscape

Where application-layer attacks aim at the service users connect to, network-layer attacks target the infrastructure in between — routers, servers and the internet link itself. These use different methods, and the Q2 data shows a distinct shift in how attackers are operating.

A diagram of a DDoS attack denying service to legitimate users

Network-layer DDoS attacks rose 109% year-over-year and 15% quarter-over-quarter. June was the heaviest month, accounting for nearly 36% of the quarter's attacks. Volumetric attacks of 100 Gbps and above climbed 8% QoQ.

Graph of the yearly distribution of network-layer DDoS attacks by month in the past 12 months

Targets and Origins

Telecommunications companies were the most targeted industry for a second straight quarter, with attacks on the sector growing 66% QoQ. Gaming came in second, followed by Information Technology and Services. The US remained the most attacked country, with attacks on US networks up 95% QoQ; China, Singapore and Germany followed.

Graph of the distribution of network-layer DDoS attack bytes by industry in 2022 Q2
Graph of the distribution of network-layer DDoS attack bytes by target country in 2022 Q2

Determining where network-layer attacks originate requires a different approach than application-layer analysis. Because no handshake is required, attackers can spoof source IP addresses freely. To account for this, Cloudflare buckets traffic by the data center where it was ingested rather than by source IP. Using this method, Palestine had the highest percentage of network-layer attack traffic, followed by Azerbaijan, South Korea and Angola.

Graph of the distribution of network-layer DDoS attacks by source country in 2022 Q2
Map of the distribution of network-layer DDoS attacks by source country in 2022 Q2

Attack Vectors

SYN floods remained the dominant attack vector, accounting for 53% of network-layer attacks. The technique abuses the stateless initial connection request of the TCP handshake; servers have no context for these new connections, making them resource-intensive to process under flood conditions.

After SYN floods, the most frequent vectors were attacks aimed at DNS infrastructure, RST floods and generic UDP floods.

Graph of the top network-layer DDoS attack vectors in 2022 Q2

Emerging Threats

Three amplification techniques stood out as the quarter's top emerging threats. Attacks abusing the CHARGEN protocol increased 378% QoQ; Ubiquiti-based attacks rose 327% QoQ; and Memcached attacks grew 287% QoQ.

Graph of the top emerging network-layer DDoS attack threats in 2022 Q2

CHARGEN, defined in RFC 864 back in 1983, is a debugging service that streams arbitrary characters until the client disconnects. Attackers spoof a victim's IP and direct streams from multiple servers at the target, flooding it with responses. The Ubiquiti attack works similarly, exploiting the vendor's device discovery protocol on UDP/TCP port 10001. Memcached, a caching system that supports UDP, offers amplification factors up to 51,200x when abused the same way.

Attack Size and Duration

Attack magnitude is measured two ways: bit rate (how much traffic) and packet rate (how many packets). High bit rates clog internet links; high packet rates exhaust the processing capacity of servers and in-line appliances, forcing them to drop packets.

By packet rate

Most network-layer attacks remained below 50,000 packets per second. Though modest at Cloudflare scale, 50 kpps can still take down an unprotected property or congest a standard Gigabit Ethernet connection. Packet-intensive attacks above 50 kpps decreased in Q2, with small attacks increasing 4% as a result.

Graph of the distribution of network-layer DDoS attacks by packet rate in 2022 Q2
Graph of the change in the distribution of network-layer DDoS attacks by packet rate quarter over quarter for 2022 Q2

By bit rate

Most attacks stayed below 500 Mbps. Attacks in the 500 Mbps-to-100 Gbps range dropped 20-40% QoQ, while attacks above 100 Gbps grew 8%. The data suggests attackers are consolidating into more extreme volumetric events while reducing mid-range activity.

Graph of the distribution of network-layer DDoS attacks by bit rate in 2022 Q2
Graph of the change in the distribution of network-layer DDoS attacks by bit rate quarter over quarter for 2022 Q2

Duration

Attacks remain predominantly short-lived: 52% lasted under 10 minutes and 40% more lasted 10-20 minutes. The remaining 8% stretched from 20 minutes past three hours. Attacks lasting over three hours increased 9%.

Graph of the distribution of network-layer DDoS attacks by duration in 2022 Q2

Attacks in the 20-60 minute range increased over 15%, and those exceeding three hours rose 12%. Short attacks are particularly dangerous because they can end before manual mitigation or on-demand services can redirect traffic. Automated, always-on protection that fingerprints and blocks traffic in real time is the only practical defense against these bursts.

Graph of the change in the distribution of network-layer DDoS attacks by duration quarter over quarter for 2022 Q2