HTTP DDoS: Meris dominates, tech and gaming take the brunt
Cloudflare’s network data for Q3 2021 shows a quarter of records and new threat patterns. The standout event was the continued activity of Meris, a botnet built from compromised MikroTik networking gear, which drove some of the largest HTTP DDoS attacks ever logged. The quarter also saw a notable uptick in network-layer assaults globally, and a distinct industry focus on software and gaming companies.
To gauge attack pressure without skewing results toward larger data centers, Cloudflare uses a “DDoS activity” rate: the share of attack traffic within total traffic (attack plus clean) seen at any observation point. All figures below are based on that normalized metric.
Application-layer attacks: a new botnet heavyweight
HTTP DDoS attacks aim to overload a web server with requests until it drops legitimate traffic or crashes. Q3’s headline statistic was a 17.2M rps attack against a financial services customer — among the largest ever recorded and attributed to Meris, a botnet name that translates from Latvian as “plague.”
Meris is built on unpatched routers and switches from MikroTik, exploiting a RouterOS vulnerability that was patched back in 2018 but remains live on many devices. Unlike the 2016 Mirai botnet, which weaponized low-power IoT devices like smart cameras, Meris harnesses networking infrastructure with far more processing power and bandwidth. That makes individual nodes more destructive in aggregate.
Still, raw power does not guarantee impact. As of this reporting, Meris had not caused major outages or infrastructure failures, despite its volume. Mirai’s 2016 takedown of the DYN DNS service remains the model for what targeted precision can accomplish, regardless of botnet size.
Industry targets: software and gaming lead
When broken down by vertical, Computer Software companies were the most targeted industry for L7 attacks in Q3. Gaming and Gambling followed as a close second, a sector that has historically drawn frequent attacks. Internet and IT companies rounded out the top four, with combined attacks across these segments rising an average of 573% quarter-over-quarter.

Source countries: China leads, but its volume drops
L7 attack origins are tracked by the geolocation of source IPs, which cannot be spoofed in HTTP requests. A high activity rate in a country often indicates the presence of botnets operating from within.
China, the US, and India were the top sources of HTTP DDoS traffic in Q3. While China held the number-one spot, its share of attack traffic actually fell 30% from Q2, with roughly one out of every 200 HTTP requests from Chinese IPs being part of an attack. Elsewhere, Brazil and Germany each saw attacks shrink by 38% quarter-on-quarter, while the US dropped 40% and Malaysia 45%.

Target countries: the US remains the focus
Looking at target geography via customer billing country data, the US led for the second consecutive quarter, followed by the UK and Canada. The latter two saw their L7 attack volumes jump significantly in Q3, a first for 2021, placing them as the second and third most-targeted nations worldwide. Earlier in the year, no data had put them in those positions.

Network-layer attacks: a worldwide increase with regional spikes
At L3/4, the picture is one of spread rather than singular events. Total DDoS attacks rose 44% worldwide compared to Q2. The Middle East and Africa region posted the largest average increase, at roughly 80%.
Morocco saw the highest DDoS activity of any country globally: three out of every 100 packets traversing its networks were part of an attack. SYN and RST floods remained the dominant vectors, but attackers also leaned heavily on Datagram Transport Layer Security (DTLS) amplification, which exploded by 3,549% quarter-over-quarter.
Separately, VoIP providers became a persistent target. Through Q3 and into the current quarter, attackers have launched large-scale campaigns aimed at taking down SIP infrastructure. These ranged from direct assaults on VoIP service providers to hits on their underlying network infrastructure, with some also tied to ransom demands.
Mirai resurfaces with terabit-scale floods
Q3 2021 marked a resurgence of the Mirai botnet. A Mirai-variant botnet launched over a dozen UDP- and TCP-based DDoS attacks that peaked multiple times above 1 Tbps, with a maximum of approximately 1.2 Tbps. The attacks targeted Cloudflare customers on the Magic Transit and Spectrum services, including a major APAC-based Internet services, telecommunications, and hosting provider, and a gaming company. All attacks were automatically detected and mitigated without human intervention.

September was the busiest month for attackers so far in 2021, accounting for over 16% of all attacks this year. Q3 overall contributed more than 38% of all attacks in 2021.
Attack sizes: bit rate and packet rate
Attack size is measured two ways. Bit rate (terabits or gigabits per second) reflects the volume of traffic delivered, attempting to clog the Internet link. Packet rate (millions of packets per second) reflects the number of packets delivered, attempting to overwhelm servers, routers, or in-line hardware. Each packet requires memory and computation to process; flooding an appliance exhausts those resources and results in dropped packets and denial of service.
The majority of attacks in Q3 were small. Nearly 89% of all attacks peaked below 50K packets per second (pps). Yet larger attacks are increasing quarter-over-quarter — attacks peaking above 10M pps rose by 142% QoQ, and attacks in the 1–10M pps range increased by 196%.


From the bit rate perspective, 95.4% of all attacks peaked below 500 Mbps. Larger bitrate attacks also grew: attacks from 500 Mbps to 1 Gbps surged 289% QoQ, and those from 1 Gbps to 100 Gbps rose by 126%. Attacks over 100 Gbps decreased by nearly 14%. Notably, all attacks over 400 Gbps took place in August, including peaks above 1 Tbps reaching as high as 1.2 Tbps.



The trend indicates that while most attacks are small in size, more attackers are acquiring resources to launch larger ones.
Attack durations and the need for automation
Duration is measured from first detection to the last packet with a given attack signature. In Q3, 94.4% of attacks lasted less than an hour, and attacks over 6 hours accounted for less than 0.4%. Attacks ranging from 1–2 hours increased 165% QoQ, though a longer duration doesn't necessarily mean a more dangerous attack.

Short attacks, especially burst attacks that flood a target within seconds, can easily evade detection. Mitigation that relies on manual analysis or on-demand traffic rerouting often finishes after the attack has already ended. Effective protection requires automated, always-on services that analyze traffic and apply real-time fingerprinting. Cloudflare's autonomous edge DDoS protection system (dosd) generates and applies a dynamically crafted rule with a real-time signature; pre-configured firewall rules for known traffic patterns take effect immediately. Analyzing traffic out-of-path ensures that mitigation adds no latency to legitimate traffic.
Attack vectors and emerging threats
SYN floods remain attackers' favorite method, comprising more than half of all observed attacks. In a SYN flood, the attacker exploits the TCP three-way handshake by sending repeated SYN packets, exhausting the server's connection table and memory for half-open connections, preventing legitimate clients from connecting. RST, ACK, and UDP floods follow as popular vectors.

Among emerging vectors, DTLS amplification attacks surged by 3,549% QoQ. Datagram Transport Layer Security (DTLS) provides security guarantees similar to TLS for connectionless datagram-based applications, making it useful for VPN connections without TCP meltdown issues. As with most UDP-based protocols, DTLS is spoofable and can be used for reflection amplification attacks aimed at network gateways.

Geographic distribution
Attack data is bucketed by the Cloudflare edge data center location where traffic was ingested, not the source IP, because attackers frequently spoof source IPs in network-layer attacks. Cloudflare's presence in over 250 cities worldwide enables geographical accuracy in reporting.

Morocco had the highest observed network attack rate, with Asian countries closely behind. An interactive map is available on the Radar DDoS Report dashboard.
VoIP attacks and ransom DDoS
The surge in DDoS attacks against VoIP service providers, some of which received ransom threats, remains ongoing as of early Q4 2021. HTTP attacks against API gateways and corporate websites have been combined with network-layer and transport-layer attacks against VoIP infrastructures.

Observed methods include:
- TCP floods targeting stateful firewalls: Used in "trial-and-error" attacks; not very effective against telephony infrastructure (mostly UDP) but very effective at overwhelming stateful firewalls.
- UDP floods targeting SIP infrastructure: Generic floods without well-known fingerprints, aimed at critical VoIP services; they may resemble legitimate traffic to unsophisticated filtering systems.
- UDP reflection targeting SIP infrastructure: Particularly effective against SIP or RTP services, capable of overwhelming Session Border Controllers (SBCs) with high-precision targeting.
- SIP protocol-specific attacks: Application-layer attacks of special concern because the resource cost of generating application errors is lower than the cost of filtering on network devices.
Ransom notes threatening attacks in exchange for bitcoin continue to target organizations. For the fourth consecutive quarter, ransomware and ransom DDoS attacks remain a germane threat. Relevant protections include DNS filtering, browser isolation, Zero Trust architecture to prevent ransomware spread, and Magic Transit for DDoS protection via BGP route redistribution without latency impact.
Building a Resilient Internet
Cloudflare’s founding mission is to help build a better Internet, a core part of which is rendering DDoS attacks a non-factor. To that end, the company has worked for over a decade to shield customers from attacks regardless of size or type. In 2017, it took a major step by introducing unmetered DDoS protection at no extra cost, bundled with every Cloudflare service and plan, including the Free tier. The intent was to ensure that any organization could remain up and protected. This move has drawn in a broad range of businesses, from small operations to large enterprises, all seeking secure, high-performance websites, applications, and networks.
However, the threat landscape extends beyond volumetric DDoS assaults. Organizations face a constant barrage of malicious bots, ransomware, email phishing, and VPN or remote access exploits. These vectors target the very infrastructure of modern online businesses—websites, APIs, applications, and networks. This reality drives the Cloudflare security portfolio, which is designed to provide coverage for everything and everyone connected to the Internet.
For more details on DDoS protection or Cloudflare’s broader network services, you can explore offerings via the dashboard or contact the team directly.



