DDoS activity hit record highs in Q3 2024
Cloudflare's 19th quarterly DDoS threat report, covering July through September 2024, shows a surge in attack volume. The company mitigated nearly 6 million DDoS attacks during the quarter, a 49% increase over the previous quarter and 55% more than the same period last year. The total for the first three quarters of 2024 now stands at 14.5 million attacks, with roughly 2,200 attacks mitigated per hour on average.
Of note, over 200 hyper-volumetric attacks exceeded 1 Tbps or 1 Bpps during the quarter. The largest attack Cloudflare detailed in the report peaked at 4.2 Tbps and lasted about a minute. This occurred on October 21, 2024 — just three weeks after the company disclosed a 3.8 Tbps attack — and was detected and mitigated autonomously by Cloudflare's DDoS defense systems.

Distribution of hyper-volumetric DDoS attacks over time

4.2 Tbps DDoS attack mitigated autonomously by Cloudflare
Attack mix and characteristics
Attack types were evenly split in Q3, with roughly half of the 6 million attacks targeting the network layer and half targeting the application layer. Network-layer attacks grew 51% quarter-over-quarter and 45% year-over-year, while HTTP attacks climbed 61% QoQ and 68% YoY.
The vast majority of attacks — 90% — were short-lived, and this held even for the largest attacks measured. However, the share of attacks lasting longer than an hour rose slightly by 7%, though these accounted for just 3% of all attacks.
Dominant vectors and botnet activity
Among network-layer attacks, SYN flood was the top vector, followed by DNS flood, UDP flood, SSDP reflection, and ICMP reflection. SSDP amplification attacks saw a dramatic 4,000% increase quarter-over-quarter. These attacks exploit UPnP-enabled devices — routers, printers, IP cameras — by spoofing the victim's IP address, causing devices to flood the target with responses. Disabling UPnP where not needed remains a basic defense.

Illustration of an SSDP amplification attack
On the application layer, known botnets launched 72% of HTTP DDoS attacks, which Cloudflare's heuristics automatically detected and mitigated. Another 13% were mitigated due to suspicious HTTP attributes, and 9% were attacks that impersonated browsers. The remaining 6% encompassed other categories, including login endpoint targeting and cache busting. These groups are not mutually exclusive; known botnets, for instance, sometimes also impersonate browsers.

Distribution of DDoS attacks in 2024 Q3
Spoofed user agents and HTTP fingerprints
In HTTP DDoS attack traffic, the Chrome browser was the most impersonated user agent, appearing in 80% of attacks; Chrome versions 118 through 121 were the most common. Attacks with no user agent at all took second place at 9%. The Go-http-client and fasthttp user agents followed, with hackney in fifth. Notably, sixth place went to HITV_ST_PLATFORM, a user agent that appears tied to smart TVs or set-top boxes — uncommon in typical attacks, suggesting compromised connected devices. The uTorrent user agent appeared in seventh place, and okhttp rounded out the list.

Top user agents used in DDoS attacks
Looking at HTTP methods, GET accounted for 89% of attack traffic, but since GET is also the most common method overall, normalizing by total traffic per method shifts the picture: nearly 12% of all DELETE requests were part of DDoS attacks. HEAD, PATCH, and GET followed in that order when measured this way. Similarly, while 80% of attack requests used HTTP/2 and 19% used HTTP/1.1, the non-standard "HTTP/1.2" version showed over half its traffic was malicious — though that version string is not an official protocol version.

Encrypted HTTPS traffic made up nearly 94% of HTTP DDoS attack traffic in Q3.

The vast majority of HTTP DDoS attacks are actually encrypted — almost 94% — using HTTPS.
Who was targeted
China was the most attacked location in Q3, with the United Arab Emirates second and Hong Kong third, followed by Singapore, Germany, and Brazil. Canada ranked seventh, ahead of South Korea, the United States, and Taiwan in tenth place.

By industry, Banking & Financial Services drew the most DDoS attacks, with Information Technology & Services second and Telecommunications, Service Providers, and Carriers third. Cryptocurrency, Internet, Gambling & Casinos, and Gaming were close behind. Consumer Electronics, Construction & Civil Engineering, and Retail completed the top ten.

Who is behind the attacks?
Our survey of attacked customers sheds light on the perpetrators. While 80% of respondents did not know who attacked them, the remaining 20% offered a breakdown that shows extortion is the leading motive. Among those who identified their attacker, 32% pointed to extortionists, 25% to competitors, and 21% to disgruntled customers or users. State or state-sponsored groups were named by 14% of respondents, and 7% admitted to inadvertently attacking themselves — a scenario that can occur, for example, when a firmware update for IoT devices causes all units to phone home simultaneously, creating a self-inflicted traffic flood.

Distribution of the top threat actors
Despite extortionists being the most commonly cited actor, Ransom DDoS attacks overall declined by 42% quarter-over-quarter, though they still rose 17% year-over-year. A total of 7% of respondents reported experiencing or being threatened by a Ransom DDoS attack, with that figure climbing to 10% — one in ten — in August.

Reports of Ransom DDoS attacks by quarter
Attack origins: locations and networks
Indonesia ranked as the largest source of DDoS attacks in Q3, followed by the Netherlands, Germany, Argentina, and Colombia. The next five spots went to Singapore, Hong Kong, Russia, Finland, and Ukraine.

For network operators, identifying malicious use of their infrastructure can be challenging. Our free threat intelligence feed helps by flagging IP addresses within their networks that have been observed participating in DDoS attacks. Based on that data, German IT provider Hetzner (AS24940) was the largest source of HTTP DDoS attacks in Q3. Linode (AS63949), the cloud platform acquired by Akamai in 2022, was second, and Florida-based Vultr (AS64515) took third place.
The remainder of the top ten were Netcup (AS197540), Google Cloud Platform (AS15169), DigitalOcean (AS14061), French provider OVH (AS16276), Stark Industries (AS44477), Amazon Web Services (AS16509), and Microsoft (AS8075).

Networks that were that largest sources of HTTP DDoS attacks in 2024 Q3
Outlook and implications
This quarter saw an unprecedented surge in hyper-volumetric DDoS attacks, with peaks reaching 3.8 Tbps and 2.2 Bpps. The pattern mirrors last year's HTTP/2 Rapid Reset campaign, where application layer attacks exceeded 200 million requests per second. These massive attacks can overwhelm Internet properties, especially those dependent on capacity-limited cloud services or on-premise solutions.
The proliferation of powerful botnets, amplified by geopolitical tensions and global events, is broadening the pool of potential targets — including organizations that historically would not have been considered at high risk for DDoS. All too often, protections are only deployed reactively, after significant damage has already been inflicted.
Our findings consistently show that organizations with comprehensive, well-prepared security strategies are substantially more resilient. Continued investment in automated defenses and a strong security product portfolio enables proactive protection against evolving threats.



