Q1 2023 DDoS Landscape: Record Volumes and a Changing Botnet Model
Distributed denial-of-service (DDoS) attacks remain one of the most disruptive threats online, and the first quarter of 2023 showed just how quickly attackers are adapting their tactics. While the volume of attacks continues to rise, the infrastructure behind these campaigns is undergoing a significant shift.
Hacktivism Takes Center Stage
The year opened with a wave of activity from pro-Russian hacktivist groups, particularly Killnet and AnonymousSudan, targeting Western banks, airports, healthcare organizations, and universities. While these groups drew significant attention and successfully disrupted unprotected services, Cloudflare observed no particularly large or novel attacks originating from them. The more significant threat activity came from other actors deploying new, more powerful attack methods.
Hyper-Volumetric Attacks Break Records
The most notable trend in Q1 was the rise of hyper-volumetric attacks. Threat actors launched campaigns that exceeded previous benchmarks, with the largest single attack peaking at over 71 million requests per second (rps). That figure surpasses the previous known world record of 46 million rps by 55%. In a separate campaign, a South American telecommunications provider was targeted by a multi-vector attack involving DNS and UDP traffic that peaked at 1.3 Tbps. The attack, part of a broader offensive from a 20,000-strong Mirai-variant botnet, lasted only a minute. The majority of the traffic originated from the US, Brazil, Japan, Hong Kong, and India. Cloudflare's systems automatically detected and mitigated the terabit-scale attack without impacting the customer's network.
The Shift to High-Performance VPS Botnets
These massive attacks are powered by a new generation of botnets that are fundamentally different from those of the past. Earlier botnets relied on hundreds of thousands or millions of compromised Internet of Things (IoT) devices, like security cameras, each contributing a small amount of traffic. While effective, those botnets required sheer numbers to generate significant disruption. The new model uses Virtual Private Servers (VPS), not IoT devices. Attackers compromise unpatched servers or gain access through leaked API credentials, allowing them to build botnets with far fewer devices. Each compromised VPS is substantially more powerful than an IoT device, making these new botnets up to 5,000 times stronger.
In response, Cloudflare has collaborated with key cloud computing providers to dismantle large portions of these VPS-based botnets. The cooperation has been effective, with no additional hyper-volumetric attacks observed since the takedowns. Cloudflare is encouraging other cloud and hosting providers to join the fight by signing up for its free Botnet Threat Feed, which provides visibility into attacks originating from within their own networks.
Key Attack Trends
- Ransom DDoS attacks remained steady, with 16% of surveyed customers reporting an attack or threat, but that figure represents a 60% increase year-over-year.
- Non-profit organizations and Broadcast Media companies were among the most targeted industries. Network-layer attacks significantly spiked against targets in Finland.
- While attacks above 100 Gbps increased by 6% quarter-over-quarter (QoQ), the most significant shift was in attack vectors. DNS-based attacks became the most popular, alongside surges in DNS amplification and GRE-based attacks.
Ransom DDoS Remains a Persistent Threat
Ransom DDoS attacks continue to be a favored tool for extortion because they are easier to execute than ransomware. Unlike a ransomware infection, which requires tricking a victim into opening a malicious file to gain a foothold, a Ransom DDoS attack requires no network intrusion. The attacker simply bombards the victim's internet properties with enough traffic to render them unavailable, then demands a Bitcoin payment to cease the attack.
Attack Targets and Sources
Attack traffic in Q1 was directed at a diverse set of geographies and industries. When normalizing for total traffic, Slovenia and Georgia were the most heavily targeted by HTTP DDoS attacks, with a fifth of their traffic being malicious. In terms of absolute volume, Israel was the top target, followed by the US, Canada, and Turkey.
At the network layer, the picture is different. China absorbed the largest share of network-layer DDoS attack traffic, closely followed by Singapore. However, when normalized by traffic volume, Finland saw 83% of its total traffic classified as attack traffic, making it the most heavily targeted country, likely tied to its recent NATO membership.
Across industries, the impact varied significantly. Internet companies saw the highest absolute volume of HTTP DDoS traffic. Yet, when looking at proportion of traffic, Non-profits and Accounting firms were the most targeted. On a regional basis, Gaming & Gambling was the top target in Asia, Europe, and the Middle East. Banking, Financial Services and Insurance (BFSI) led attacks in South and Central America, while Marketing & Advertising was the most targeted sector in North America.
For L3/4 attacks, Information Technology and Services was the primary target by volume. The most striking data point was for Broadcast Media, where nearly every second byte transmitted to those companies was confirmed as L3/4 DDoS attack traffic.
The source of attacks also shifted. While US IP addresses generated the most HTTP DDoS traffic by absolute volume, Finland was the largest source when measured as a percentage of its overall traffic. On the network layer, Vietnam was the dominant source, with almost a third of all L3/4 traffic at its data centers being malicious.
Attack Sizes and Duration
The vast majority of network-layer DDoS attacks are short-lived and low-volume. 86% of these attacks conclude within 10 minutes, and 91% never exceed 500 Mbps. Only one out of every fifty attacks surpasses 10 Gbps, and merely one in a thousand exceeds 100 Gbps.

While most attacks fall into these smaller buckets, the frequency and size of larger attacks are on the rise. The growth rate for attacks exceeding 100 Gbps has slowed from last quarter's 67% QoQ increase to a 6% increase this quarter. However, all volumetric attack size brackets except for the "small" category experienced positive growth. The most significant jump was in the 10–100 Gbps range, which saw an 89% increase QoQ.

Leading Attack Vectors
This quarter saw a major change in the distribution of network-layer attack vectors. DNS-based attacks (floods and amplification/reflection) became the most common vector, accounting for 30% of all L3/4 attacks. SYN floods dropped to second place with a 22% share, and UDP-based attacks followed closely at 21%.

Resurgent Threats
The reappearance of older attack methods indicates that threat actors continue to exploit decade-old vulnerabilities, perhaps betting on organizations having dropped protections against outdated techniques. This quarter saw notable spikes in SPSS-based DDoS attacks, DNS amplification, and GRE-based attacks.

SPSS-Based Attacks Spike 1,565% QoQ
The IBM SPSS software suite relies on the Sentinel RMS License Manager for licensing. Vulnerabilities identified in 2021 (CVE-2021-22713 and CVE-2021-38153) remain exploitable for reflection DDoS attacks. Attackers send crafted license requests to the server, which generates responses far larger than the original queries. By spoofing a victim's IP address, the amplified responses flood the target's network, disrupting availability of dependent software like IBM SPSS Statistics. Applying available patches is essential to prevent exploitation.
DNS Amplification Grows 958% QoQ
DNS amplification attacks exploit misconfigured open DNS resolvers that accept recursive queries from any source. Attackers send requests that generate large responses, spoofing the victim's IP to direct the amplified traffic at them. Because this attack traffic can be difficult to distinguish from legitimate DNS queries, blocking it at the network level is challenging. Mitigation includes properly configuring resolvers, rate-limiting, and filtering traffic from known attackers.
GRE-Based Attacks Up 835% QoQ
GRE-based DDoS attacks leverage the Generic Routing Encapsulation protocol by creating multiple tunnels between compromised hosts to flood a target. The traffic can appear legitimate, and source IP spoofing complicates network-level filtering. These attacks risk downtime and business disruption. Effective defense relies on advanced traffic filtering tools that detect attack characteristics, alongside rate limiting and IP filtering.
The Threat Landscape
Longer and larger volumetric attacks are becoming more frequent across industries, with Non-profit and Broadcast Media companies being top targets. DNS-based attacks are also more prevalent. Because DDoS attacks are bot-driven, automated detection and mitigation remain critical. Cloudflare's systems offer constant protection, and we have provided free and unlimited DDoS defense since 2017 as part of our mission to build a better, more secure Internet. We invite you to join our DDoS Trends Webinar for more insights.
A Note on Methodology
Ransom DDoS Insights: After each automatically mitigated attack, customers are surveyed about threats or ransom notes. Over the past two years, we collected an average of 164 responses per quarter, which forms the basis for our Ransom DDoS percentage calculations.
Geographical and Industry Insights: At the application layer, we examine attacking IP addresses to determine origin since they cannot be spoofed. At the network layer, where spoofing is possible, we rely on the location of our data centers (over 285 worldwide) that ingest attack packets. For target insights, we group attacks by our customers' billing country and industry from our CRM system.
Total Volume vs. Percentage: We analyze both total attack traffic volume and the "attack activity rate" — the percentage of attack traffic relative to a country's or industry's total traffic. This normalization removes bias toward entities with naturally higher traffic levels.
Attack Characteristics: To report attack size, duration, vectors, and emerging threats, we bucket attacks and present each bucket's share of the total.
Disclaimer: A "top source country" indicates where attack IP addresses are mapped, which may point to exit or botnet nodes rather than the attacker's true location. A "top target country" means organizations using that country as their billing country were targeted, not necessarily that a nation-state was attacked.



