The 2023 Q3 DDoS Landscape: Rapid Reset and Record Volumes
Cloudflare's third-quarter threat data for 2023 shows a security environment dominated by a single, sustained campaign. The company reported one of the most sophisticated and persistent DDoS attack waves it has ever recorded, driven by exploitation of the HTTP/2 protocol and a new class of high-efficiency botnets.
The headline figure is a massive increase in attack traffic. HTTP DDoS attack volume grew by 65% quarter-over-quarter, with Cloudflare's systems detecting and mitigating a total of 8.9 trillion HTTP requests. This spike was fueled largely by the hyper-volumetric campaign described below. Layer 3/4 (L3/4) attacks also saw a rise, up 14% from the previous quarter.

The HTTP/2 Rapid Reset Campaign
Beginning in late August 2023, Cloudflare—along with other vendors—became the target of a sophisticated attack exploiting a zero-day vulnerability in HTTP/2 known as Rapid Reset (CVE-2023-44487). HTTP/2 is the dominant protocol version, accounting for 62% of HTTP traffic, which makes it a significant vector. The flaw allows an attacker to cancel requests rapidly, creating a highly efficient method for overwhelming server resources.

The campaign involved thousands of hyper-volumetric attacks, with the average attack rate reaching 30 million requests per second (rps). The scale of these attacks was unprecedented: approximately 89 individual attacks peaked above 100 million rps, with the largest single attack hitting 201 million rps—a figure three times higher than the previous record of 71 million rps from earlier in 2023.

These attacks were enabled by a shift in botnet architecture. Rather than relying on massive fleets of compromised Internet-of-Things (IoT) devices, attackers leveraged virtual machines (VMs) from cloud computing platforms. This new approach is significantly more potent; Cloudflare estimates that exploiting HTTP/2 from VM-based botnets can generate up to 5,000 times more force per node than traditional methods. A botnet of just 5,000 to 20,000 nodes was sufficient to launch these hyper-volumetric attacks, a stark contrast to older IoT botnets that required millions of devices to achieve far lower request rates.

Analysis of the two-month campaign shows that Cloudflare's own infrastructure was the primary target, absorbing 19% of all attacks. The Gaming and Gambling industry was the second most targeted sector at 18%, followed by VoIP providers at 10%.

Significant L3/4 Attacks
Beyond the HTTP/2 campaign, Q3 also saw an increase in large volumetric L3/4 attacks, with numerous incidents reaching terabit-per-second speeds. The largest attack of the quarter peaked at 2.6 Tbps. This was a UDP flood launched by a Mirai-variant botnet, targeting Cloudflare's free public DNS resolver, 1.1.1.1. The company also observed a rise in DDoS activity against Israeli and Palestinian media, financial, and government websites in the wake of recent geopolitical events.

Attack Origins
The source of HTTP DDoS attacks by raw volume remained relatively consistent. The US was the largest source, accounting for 1 out of every 25 HTTP DDoS requests, with China in second place. Brazil rose to the third spot, displacing Germany to fourth.

However, the view changes when attack traffic is normalized against a country's overall traffic to remove the bias of population and internet usage. In this analysis, the US does not appear in the top ten. Instead, Mozambique was the top source for the second consecutive quarter, with one in every five HTTP requests originating from the country being part of an attack. Egypt held the second spot with 13%, followed by Libya and China in third and fourth, respectively.

For L3/4 attacks, Cloudflare's data uses the location of its data centers rather than source IPs, which can be spoofed. By this measure, roughly 36% of all L3/4 attack traffic ingressed through the US, with Germany (8%) and the UK (5%) a distant second and third.

When normalizing this L3/4 data, Vietnam dropped from its long-held first-place position to second. New Caledonia took the top spot, with an extraordinary two out of every four bytes ingested in Cloudflare's data centers there classified as attack traffic.

Targeted Industries
By absolute volume of HTTP DDoS attack traffic, the Gaming and Gambling industry was the most targeted in Q3, overtaking the Cryptocurrency sector. More than 5% of all HTTP DDoS traffic was directed at this industry.

The ranking shifts significantly when attacks are measured against each industry's own traffic volume, rather than as a share of the global total. Gaming and Gambling, despite having the largest raw attack volume, generates so much legitimate user traffic that it falls out of the top ten in this relative comparison.
Instead, the most targeted sector was Mining and Metals, where 17.46% of all traffic was determined to be part of a DDoS attack. Non-profits were a close second, with 17.41% of their traffic being malicious. This is particularly relevant to Cloudflare's Project Galileo, which offers free protection to vulnerable organizations. Cloudflare mitigated an average of 180.5 million cyber threats per day against over 2,400 Galileo-protected sites in 111 countries during the quarter.

The Pharmaceuticals, Biotechnology, and Health industry ranked third, followed by US Federal Government websites, where nearly one in every ten requests was an attack. Cryptocurrency was the fifth most targeted industry in this relative analysis, with Farming and Fishery close behind.
Industry Targets by Region
Regional threat landscapes continue to shift, with notable changes in which sectors are drawing the heaviest attack volumes. In Africa, Media Production companies were the most targeted, pushing Telecommunications down to fourth after two quarters at the top. The Banking, Financial Services and Insurance (BFSI) sector held second place, with Gaming and Gambling in third. Across APAC, the Cryptocurrency industry remained the most attacked for a second consecutive quarter, followed by Gaming and Gambling and then Information Technology and Services.
Europe’s Gaming and Gambling industry retained its position as the most attacked for the fourth straight quarter, with Retail and Computer Software companies completing the top three. Latin America presented a striking outlier: Farming accounted for 53% of all attacks directed at the region, with Gaming and Gambling and Civic and Social Organizations far behind. In the Middle East, Retail led, trailed by Computer Software and Gaming and Gambling. North America saw Marketing and Advertising drop from first to second after two quarters, as Computer Software took the top spot and Telecommunications moved into third. Oceania’s Telecommunications industry absorbed over 45% of all regional attack traffic, with Cryptocurrency and Computer Software companies in second and third.
Network-Layer (L3/4) Attack Targets
When examining attacks at the network layer, Information Technology and Internet industry systems were overwhelmingly favored, drawing almost 35% of all L3/4 DDoS attack traffic by bytes. Telecommunications came in a distant second at 3%, with Gaming and Gambling and BFSI rounding out the top four.

Normalizing these figures against each industry’s overall traffic paints a different picture. Under that lens, the Music industry ranks first, with Computer and Network Security companies, Information Technology and Internet firms, and Aviation and Aerospace following in order.

Geographic Targets by Layer
For HTTP-based DDoS attacks, the United States remained the top destination, drawing nearly 5% of global attack traffic. Singapore and China took second and third place. When attack traffic is instead measured as a proportion of a country’s total inbound traffic, several small island territories surface as the primary victims. Anguilla topped this list, with over 75% of all traffic to its websites classified as HTTP DDoS attacks. American Samoa and the British Virgin Islands followed, ahead of Algeria, Kenya, Russia, Vietnam, Singapore, Belize, and Japan.


At the network layer, China stayed the primary target for a second quarter running, absorbing 29% of all L3/4 attacks. The US came in second at just 3.5%, with Taiwan at 3% in third.

A normalized look at network-layer traffic confirms China’s dominance: 73% of all traffic to Chinese networks was attack traffic. The US fell out of the top ten entirely in that comparison. The Netherlands recorded the second-highest attack ratio, with 35% of its inbound traffic, followed by Thailand, Taiwan, and Brazil.

Leading Attack Vectors
DNS-based DDoS attacks were again the most common vector for the second consecutive quarter, making up nearly 47% of all attacks — a 44% increase over the previous quarter. SYN floods, RST floods, UDP floods, and Mirai attacks held the next positions in the rankings.

Emerging Threats
Beyond the dominant vectors, less common attack methods showed significant growth this quarter. Many rely on UDP-based protocols for amplification and reflection, where attackers spoof a victim’s IP address and bounce traffic off vulnerable servers. One notable variation is the “DNS Laundering” attack, which bombards an authoritative DNS server with randomized subdomain queries. Since the prefixes are never reused, recursive resolvers cannot cache responses and forward every query upstream until the target is overwhelmed.


Three emerging methods stood out by growth rate. Multicast DNS (mDNS) attacks jumped 456% compared to the prior quarter, exploiting misconfigured devices that respond to spoofed unicast queries from outside the local network. Constrained Application Protocol (CoAP) attacks rose 387%, leveraging multicast support or weak configurations in lightweight IoT devices to generate amplified traffic. Attacks abusing the Encapsulating Security Payload (ESP) protocol of IPsec climbed 303%, as attackers look for systems that can be 眉used to reflect traffic toward a target.
Ransom DDoS Attack Trends
Ransom DDoS attacks, which demand payment under threat of network disruption, continued a year-long decline in Q3. Only about 8% of surveyed Cloudflare customers reported being threatened or attacked by this method. The downturn may reflect a growing recognition among threat actors that organizations will refuse to pay. Historical data suggests caution, however: Q4 figures over the past three years show a pronounced seasonal spike in November and December, when as many as one in four respondents reported being targeted.



Hardening Defenses
The quarter’s record-breaking attack volumes were driven largely by the hyper-volumetric HTTP/2 campaign. Cloudflare customers using its HTTP reverse proxy (CDN/WAF) already benefit from protections against this traffic. For any HTTP application, an automated, always-on HTTP DDoS protection service is strongly advised as a baseline defense.
Security is best treated as an ongoing process. In addition to automated DDoS mitigation, a layered deployment of firewall rules, bot detection, API protection, and caching can minimize the impact of an attack. Organizations should review response recommendations, use guided learning paths to secure applications, and adopt preventative measures before an incident occurs.



