DDoS Landscape: The Closing Months of 2021

2021 was a relentless year for distributed denial-of-service (DDoS) activity, punctuated by major ransomware campaigns against critical infrastructure and the discovery of the Log4j2 vulnerability (CVE-2021-44228) in December. As the year ended, the attack surface continued to expand, with new botnets and record-breaking assaults dominating the threat landscape.

The following data, gathered from attacks automatically detected and mitigated by Cloudflare’s DDoS protection systems, highlights key trends from the fourth quarter of 2021. The "DDoS activity" rate referenced here is calculated as the percentage of attack traffic out of the total traffic observed over the network, a metric designed to normalize data across data centers of varying sizes.

Ransom-Driven Extortion

Ransom DDoS attacks, where attackers demand payment to halt an assault, saw a significant surge in Q4 ‘21, increasing by 29% year-over-year and a massive 175% quarter-over-quarter. Attackers were not always subtle; they often sent ransom notes in advance of or during an attack.

Graph of ransom DDoS attacks by quarter

This escalation was particularly pronounced in December, when a survey of attacked customers showed that 32% of respondents—nearly one in three—reported receiving a ransom demand.

Graph of ransom DDoS attacks by month

HTTP DDoS attacks aim to overwhelm web servers with requests, preventing them from processing legitimate user traffic. These attacks often rely on botnets, as source IP addresses cannot be spoofed at the application layer, making them traceable to specific regions.

BLOG-893 Embedded Image - IOMYBS

Targeted Sectors and Origins

The Manufacturing industry was the most heavily targeted sector in Q4 ‘21, experiencing a staggering 641% increase in attacks compared to the previous quarter. The Business Services and Gaming/Gambling industries followed as the second and third most targeted industries, respectively.

Graph of the distribution of HTTP DDoS attacks by industry in Q4

For the fourth consecutive quarter, China was the top source of application-layer attack traffic, with more than three out of every thousand HTTP requests originating from Chinese IP addresses being part of an attack. The United States held second place, followed by Brazil and India.

Graph of the distribution of HTTP DDoS attacks by source country in Q4

Looking at the target side, organizations in the United States were the most frequent victims of HTTP DDoS attacks for the third time in a row in 2021, followed by Canada and Germany.

Graph of the distribution of HTTP DDoS attacks by target country in Q4

New and notable botnets, such as Meris, emerged during this period, launching some of the largest HTTP attacks ever recorded, including a 17.2 million requests-per-second (rps) attack that was automatically mitigated.

The fourth quarter was the busiest of 2021 for network-layer attacks, which target the infrastructure itself. In fact, December 2021 alone saw more attacks than all those observed in the entire first or second quarters of the year. While the majority of these events were small, terabit-strong attacks became increasingly common, with dozens automatically mitigated at peaks over 1 Tbps. The largest recorded assault peaked at just under 2 Tbps, the biggest ever seen on the Cloudflare network.

A persistent ransom DDoS campaign specifically targeted VoIP providers globally throughout the quarter, with November being a particularly active month. In terms of attack origins, Moldova saw a fourfold increase in activity quarter-over-quarter, making it the country with the highest percentage of network-layer DDoS traffic.

SYN and UDP floods remained the most frequent attack vectors. However, emerging threats grew significantly, with SNMP-based attacks increasing by nearly 5,800% compared to Q3 ‘21.

Network-Layer Attacks: Size, Volume, and Duration

Network-layer (L3/4) attacks target the infrastructure that connects services to users, aiming to saturate internet links or exhaust the processing capacity of in-line devices like routers and servers. They are measured by bit rate (the volume of traffic, typically in Gbps or Tbps) and packet rate (the number of packets, in millions per second, or mpps). Attacks with a high bit rate clog the link; those with a high packet rate overwhelm the hardware that must inspect each packet, forcing it to drop traffic and causing service disruption.

In November, Cloudflare's systems automatically detected and mitigated a nearly 2 Tbps multi-vector attack combining DNS amplification and UDP floods. The attack, which lasted roughly one minute, was launched from approximately 15,000 bots running a variant of the original Mirai code on IoT devices and unpatched GitLab instances.

Graph of a network-layer DDoS attack that peaked at almost 2 Tbps

December proved to be the busiest month of 2021 for network-layer attackers. More than 43% of all network-layer attacks for the year took place in Q4, with the total number of attacks in December alone surpassing all of Q2 and nearly matching Q1. Activity dipped slightly in October, then nearly doubled in November, coinciding with the Chinese Singles' Day, Thanksgiving, Black Friday, and Cyber Monday. Attack volumes continued to rise into the final days of December.

Graph of the distribution of network-layer DDoS attacks by month in 2021

An interesting pattern emerged when correlating frequency with intensity: as the number of attacks increases, their size and duration tend to decrease. For most of the year, attacks were relatively infrequent but powerful — for example, attacks ranging from 1–10 mpps grew by 196% in Q3. In Q4, however, the distribution shifted. A full 91% of all attacks peaked below 50,000 pps — a modest rate that nevertheless remains sufficient to take down unprotected properties. Larger packet-intensive attacks, over 1 mpps, decreased by up to 48% quarter-over-quarter, while those below 50K pps increased by 2.36%.

Graph of the distribution of network-layer DDoS attacks by packet rate in Q4
Graph of the change in the distribution of network-layer DDoS attacks by packet rate quarter over quarter

The same trend held for bit rates. While terabit-strength attacks are becoming part of the landscape — the largest observed peaked just below 2 Tbps — the vast majority of attacks remained small: 97.2% peaked below 500 Mbps. Attacks above that threshold fell by 35–57% quarter-over-quarter.

Graph of the distribution of network-layer DDoS attacks by bit rate in Q4
Graph of the change in the distribution of network-layer DDoS attacks by bit rate quarter over quarter

Attack durations have also contracted. In Q4, 98% of all network-layer attacks lasted less than one hour, reinforcing the need for automated mitigation. Burst attacks, which deliver a massive flood within seconds, can be over before a human analyst or an on-demand traffic-rerouting service can respond. Post-attack rule adjustments are reactive; the only effective defense against these short-lived events is an always-on service that uses real-time fingerprinting to filter malicious traffic as it begins.

Graph of the distribution of network-layer DDoS attacks by duration in Q4

Top Attack Vectors

For the first time in 2021, SYN floods did not dominate the field. They still claimed first place, but their share of network-layer attacks dropped 38% quarter-over-quarter to 34%. Close behind were UDP floods, which jumped from fourth place in Q3 to second in Q4, accounting for 32% of attacks — a 1,198% increase. These attacks bombard a server with UDP packets to exhaust its processing ability, and can also overwhelm stateful firewalls protecting the target.

The third most frequent vector in Q4 was an unexpected entrant: SNMP-based attacks. Simple Network Management Protocol, a UDP-based protocol on port 161 used to manage network devices, was abused in reflection attacks. By spoofing a target's IP address in SNMP queries, attackers cause numerous devices to respond to the target, amplifying traffic into a denial-of-service condition.

MSSQL-based attacks, which abuse the Microsoft SQL Server Resolution Protocol on UDP port 1434, also emerged as a notable reflection vector. Both SNMP and MSSQL attacks follow the same amplification pattern: spoofed queries generate large responses directed at the victim.

Graph of the top emerging network-layer DDoS attack threats Q4, 2021

Geographic Distribution

To gauge attack origin, Cloudflare analyzes traffic at the edge data center where it is ingested rather than by source IP — a critical distinction, as attackers routinely spoof source addresses in network-layer floods, making that attribution unreliable. With data centers in over 250 cities worldwide, geographic accuracy is maintained by viewing the attack data at the point of ingestion.

Graph of the distribution of network-layer DDoS attacks by source country in Q4, 2021
Graph of the distribution of network-layer DDoS attacks by source country in Q4. 2021.

Notably, Moldova saw a dramatic rise in activity, with attacks observed there quadrupling and making the country the source of the highest percentage of network-layer DDoS activity in Q4. A full interactive breakdown is available via an interactive map.

Automated, always-on DDoS protection remains the only practical defense against the breadth of attack types and volumes observed in Q4, which included short bursts, terabit-scale floods, and reflection attacks leveraging SNMP and MSSQL. Free, unmetered mitigation has been a staple of Cloudflare's offering since 2017, ensuring organizations of all sizes can defend against the full spectrum of attack techniques.