A quarter of targeted, multi-vector DDoS campaigns

Throughout Q2 2023, Cloudflare's network — which spans over 300 cities across more than 100 countries and handles over 63 million HTTP requests per second at peak — observed a DDoS landscape marked by coordinated hacktivist campaigns, a sharp rise in DNS-based attacks, and increasingly sophisticated HTTP flood techniques designed to evade mitigation systems.

Among the notable events: pro-Russian hacktivist groups REvil, Killnet, and Anonymous Sudan joined forces under the banner "Darknet Parliament" to target Western financial institutions, including banks and the SWIFT network. Cloudflare detected and automatically mitigated roughly 10,000 attacks linked to this campaign against its protected websites. Despite the group's stated focus on finance, the most targeted industries were Computer Software, Gambling & Casinos, and Gaming, with Telecommunications and Media rounding out the top five. The largest attack in this campaign peaked at 1.7 million requests per second, with an average of 65,000 rps — minuscule compared to the record 71 million rps attack mitigated earlier this year, but still potentially damaging for unprotected sites.

Also this quarter, an ACK flood attack from a Mirai-variant botnet of approximately 11,000 IP addresses peaked at 1.4 Tbps against an American ISP. Though it lasted only two minutes, the broader trend shows attacks lasting over three hours increased 103% quarter-over-quarter.

The rise of sophisticated HTTP DDoS attacks

HTTP DDoS attacks increased 15% quarter-over-quarter, despite a 35% year-over-year decrease. More concerning than the volume is the sophistication. Threat actors have begun to closely imitate real browser behavior while introducing a high degree of randomization across properties such as user agents and JA3 fingerprints — a tactic previously associated with state-sponsored groups. Many of these attacks also deliberately keep request rates low to blend in with legitimate traffic.

Targets of these advanced campaigns have included a large VoIP provider, a leading semiconductor company, and a major payment processing firm. Effective defense against such attacks requires automated protection that uses threat intelligence, traffic profiling, and statistical or machine-learning analysis to distinguish malicious from benign traffic. Where possible, expanding caching can also reduce the strain on origin servers.

DNS laundering: a growing challenge for authoritative servers

DNS remained the most common attack vector, accounting for 32% of all DDoS attacks in Q2. Among DNS-based attacks, Cloudflare flagged a worrying increase in "DNS Laundering" attacks — a technique that exploits the trust placed in reputable recursive resolvers.

In this attack model, the threat actor sends queries for randomized subdomains of a victim's domain. Because each prefix is unique, recursive resolvers such as Google's 8.8.8.8 or Cloudflare's 1.1.1.1 cannot cache responses and must forward every query to the victim's authoritative DNS server, which eventually gets overwhelmed. Defense is complicated because administrators can neither block the recursive resolvers (they are legitimate services) nor block all queries to the affected domain (legitimate traffic must be preserved).

Recent victims include a large Asian financial institution and a North American DNS provider. Protecting authoritative DNS infrastructure requires precise, automated mitigation strategies — often through a managed DNS service or a DNS reverse proxy. For the most sophisticated variants, statistical analysis of historical traffic patterns is needed to separate legitimate queries from malicious ones.

In addition, DDoS attacks exploiting the Mitel vulnerability (CVE-2022-26143) surged 532%, and attacks against cryptocurrency companies rose 600% quarter-over-quarter.

DDoS threat report for 2023 Q2

VM-Based Botnets Drive Hyper-Volumetric Attacks

The composition of botnets is shifting. Instead of armies of IoT devices, attackers are now assembling fleets of Virtual Machines (VMs) and Virtual Private Servers (VPS). This evolution in botnet "DNA" produces attacks that can be up to 5,000 times more powerful than those generated by IoT-based networks.

BLOG-1917 Embedded Image - qEwlu1

Because each VM possesses far greater computational and bandwidth resources than a typical IoT device, these botnets can generate hyper-volumetric attacks with a much smaller fleet. This new generation of botnets has already been responsible for some of the largest recorded DDoS attacks, including the 71 million request-per-second event, and has targeted major organizations such as an industry-leading gaming platform provider.

Introducing Cloudflare’s free Botnet Threat Feed for service providers

In response, Cloudflare states it has collaborated with prominent cloud computing providers to neutralize significant components of these botnets. Since that intervention, no further hyper-volumetric attacks from these specific networks have been observed. The company is inviting cloud providers, hosting companies, and other service providers to join its free Botnet Threat Feed to gain visibility into malicious activity originating from their own networks and to aid in collective takedown efforts.

"Startblast" and Other Emerging Vectors

A known vulnerability in the Mitel MiCollab business phone system, identified as CVE-2022-26143 (dubbed TP240PhoneHome), continues to be a viable attack vector. The exploit, disclosed in March 2022, abuses an unauthenticated UDP port to issue a startblast debugging command. This command reflects traffic off the server with an amplification factor as high as 220 billion percent.

BLOG-1917 Embedded Image - 70zrRK

While the number of exposed devices is limited to a few thousand and attacks must run serially, the amplification potential is significant. Beyond this, the quarter saw a 403% increase in DDoS attacks abusing the TeamSpeak3 protocol, a VoIP service popular with gamers. Such attacks are often used by rival groups to disrupt communication during real-time multiplayer games.

BLOG-1917 Embedded Image - oLzNmw

Top Sources of Attack Traffic

In Q2, HTTP DDoS attacks increased by 15% quarter-over-quarter (QoQ), though they decreased by 35% year-over-year (YoY). Network-layer DDoS attacks decreased by approximately 14% QoQ.

BLOG-1917 Embedded Image - yHGk8I

By total volume, the US was the largest source of HTTP DDoS attacks, with China and Germany following in second and third place.

BLOG-1917 Embedded Image - ovZo3R

However, normalizing attack traffic by a country’s overall traffic reveals a different pattern. When adjusted for bias, the US drops out of the top ten entirely. Instead, Mozambique, Egypt, and Finland lead as the sources of the most HTTP DDoS attack traffic relative to their total traffic, with nearly a fifth of all HTTP traffic from Mozambican IPs being part of an attack.

BLOG-1917 Embedded Image - oVj2vA

At the network layer, Vietnam remained the largest source of L3/4 DDoS attacks for the second consecutive quarter, with its share of attack bytes increasing by 58% QoQ. Over 41% of all bytes ingested in Cloudflare's Vietnam data centers were part of these attacks.

BLOG-1917 Embedded Image - 48cI6B

Targeted Industries: Volume vs. Share

Cryptocurrency websites were hit with the largest share of HTTP DDoS attack traffic by volume, seeing a 600% increase in attacks compared to the prior quarter. Gaming and Gambling sites were the second most targeted, followed by Marketing and Advertising.

BLOG-1917 Embedded Image - 58o1Ph

When looking at attack traffic as a percentage of an industry's total traffic, the picture shifts. Management Consulting firms jumped to first place, with 18.4% of their traffic identified as DDoS attacks. Non-profit organizations were close behind at 17.6%, an increase of 46% QoQ. These non-profits are often protected under Project Galileo, which celebrated its ninth anniversary this year.

BLOG-1917 Embedded Image - 8cFTeI

Industries targeted by L3/4 attacks tell a distinct story, with the Information Technology and Services sector seeing nearly a third of all inbound bytes classified as malicious. The Music industry was the second most targeted, followed by Broadcast Media and Aviation & Aerospace.

BLOG-1917 Embedded Image - XWbEBM

Industry Targets by Region

BLOG-1917 Embedded Image - WIW5OY

Regional analysis shows significant variation:

  • Africa: The Telecommunications industry was the most attacked for the second consecutive quarter, followed by BFSI.
  • Asia: Cryptocurrency took the lead, displacing Gaming and Gambling to second place for the first time in two quarters.
  • Europe: Gaming & Gambling remained the top target for the third straight quarter.
  • Latin America: Half of all attack traffic was aimed at the Sporting Goods industry, a shift from BFSI in the prior quarter.
  • Middle East: Media & Newspaper industries were the primary targets.
  • North America: Marketing & Advertising firms were most targeted for the second quarter running.
  • Oceania: The Biotechnology industry was the top target, having previously been Health & Wellness.

Geographic Targets of Attacks

In Q2, the US regained its position as the most attacked country by total HTTP DDoS traffic volume, followed by Canada and Singapore. Israel, which had led the previous quarter, saw attacks decrease by 33%, placing it fourth.

BLOG-1917 Embedded Image - BspfQ0

However, when data is normalized per country, Palestine emerges as the most attacked location, with nearly 12% of its web traffic being part of DDoS attacks.

BLOG-1917 Embedded Image - vmDEKf

At the network layer, there was a major shift last quarter when Finnish networks were the primary target, likely correlated with the country's NATO integration talks—at that time, 83% of Finland's incoming traffic was malicious. This quarter, Finland has dropped out of the top ten. Instead, Chinese networks under Cloudflare protection are now the primary target, with almost two-thirds of byte streams being hostile. Switzerland follows, with half of its inbound traffic constituting attacks, and Turkey is third with a quarter of its traffic identified as malicious.

BLOG-1917 Embedded Image - MveU2Z

Ransom DDoS: A Simpler Extortion Playbook

Ransom DDoS attacks differ fundamentally from ransomware. Ransomware typically relies on social engineering — luring a victim into opening a malicious attachment or clicking a compromised link that then locks, deletes, or leaks files until payment. Ransom DDoS removes that complexity for the attacker. There's no need for deceptive emails, no breach of the network, and no access to corporate resources. The attack simply floods a target until a ransom is paid, making it a low-cost, high-impact extortion method.

During the last quarter, reports of Ransom DDoS decreased. One out of ten survey respondents said they had been threatened with or subjected to a Ransom DDoS attack.

BLOG-1917 Embedded Image - 7OOdac
BLOG-1917 Embedded Image - GqoqNw

Attack Windows Are Shrinking

The sophistication of DDoS attacks has escalated alarmingly in recent months, and the largest, most advanced attacks may last only seconds. That window is shorter than a human response time — before a PagerDuty alert even fires, the attack has ended and the damage is done. Recovery, however, takes far longer than the attack itself; like a boxer who needs a while to recover from a punch that lands in a fraction of a second.

Security is not a single product or a single click, but a process of layered defense that reduces risk of impact. Cloudflare's automated DDoS defense systems, combined with capabilities such as firewall, bot detection, API protection, and caching, are designed to keep clients operational during an attack so they can stay focused on core business. The threat landscape is evolving and increasingly complex, demanding more than quick fixes; multi-layered defenses and automatic protection are the counterweight.

Methodology Notes

Ransom DDoS measurements

Cloudflare's systems analyze traffic continuously and apply automatic mitigation when DDoS is detected. Each attacked customer is prompted with an automated survey covering the nature of the attack and the success of mitigation. One question asks whether the respondent received a threat or ransom note. Over two years, Cloudflare has averaged 164 responses per quarter; those responses drive the Ransom DDoS percentage.

Geography and industry data

At the application layer, the attacking IP addresses indicate the origin country, because IP spoofing is not possible at that layer. At the network layer, source addresses can be spoofed, so Cloudflare instead uses the location of its data centers — over 285 worldwide — where the attack packets were ingested.

For both layers, target country is derived from customers' billing country, and target industry from the customer relations management system. This shows which countries and industries receive more attacks.

For source and target insights, two views are used: total attack traffic compared to all traffic, and the percentage of attack traffic toward or from a given country or industry. The normalized "attack activity rate" removes the bias of high-traffic regions that naturally attract more attack volume.

Attack characteristics and limitations

Attack size, duration, vectors, and emerging threats are bucketed by count, with the share of each bucket reported out of the total. The Radar component instead trends these by number of bytes. Because attacks vary greatly in size, these two approaches can produce differing trends by design.

When describing a top source or target country, it means organizations using that country for billing were targeted, not that the nation itself was attacked. Likewise, attack origin reflects IP addresses mapped to a country, not necessarily a state-sponsored launch. Threat actors run global botnets, frequently using VPNs and proxies to hide location. A source country likely indicates where exit nodes or botnet nodes are present, not who is behind the attack.