Meet Mantis: The Small But Mighty Botnet Behind Record DDoS Attacks

In June 2022, Cloudflare mitigated the largest HTTPS DDoS attack ever recorded — a barrage of 26 million requests per second. Since then, the company has been tracking the botnet responsible, which it calls "Mantis," and has observed it launching attacks against nearly a thousand Cloudflare customers.

The name is fitting. Much like the mantis shrimp — a small creature under 10 cm long capable of striking with 1,500 Newtons of force at 83 km/h — the Mantis botnet achieves outsized impact with a surprisingly small fleet. It operates roughly 5,000 bots, yet generates the most powerful HTTP DDoS attacks Cloudflare has ever seen.

What makes this especially remarkable is the attack vector: HTTPS. Generating 26 million HTTP requests per second is difficult enough without the computational overhead of establishing TLS-encrypted connections. Mantis managed it over HTTPS, averaging 5,200 requests per second per bot. That extra cost is a testament to the resources each bot brings to the table.

Unlike traditional botnets built from compromised IoT devices like DVRs, cameras, or smoke detectors, Mantis hijacks virtual machines and powerful servers. Each bot offers far greater computational capacity, which compounds into the collective strength behind these attacks.

Mantis represents the next evolutionary step from the Meris botnet. While Meris relied on MikroTik devices, Mantis has expanded to include a variety of VM platforms and supports running multiple HTTP proxies to launch its assaults. The name reflects both its lineage and its nature: this evolution hits hard and fast.

Attack Patterns and Targets

HTTP DDoS attacks have been on the rise, increasing by 72% in the past quarter — and Mantis has been a significant contributor. Over the past month alone, it launched more than 3,000 HTTP DDoS attacks against Cloudflare customers.

The botnet shows clear targeting preferences. The Internet & Telecommunications industry bore the brunt, absorbing 36% of attack share. The News, Media & Publishing sector came in second, followed by Gaming and Finance.

Geographically, over 20% of attacks targeted US-based companies, with more than 15% aimed at Russia-based firms. Turkey, France, Poland, and Ukraine each accounted for less than five percent of the attacks.

Defending Against Mantis-Style Attacks

Cloudflare's automated DDoS protection system uses dynamic fingerprinting to detect and mitigate attacks. This capability is exposed to customers through the HTTP DDoS Managed Ruleset, which is enabled by default. For users who haven't modified their settings, no action is needed — protection is already active.

For those seeking to optimize further, Cloudflare recommends reviewing its best practices for DoS preventive measures and guidance on responding to active DDoS attacks.

Organizations using only Magic Transit or Spectrum who also operate HTTP applications outside of Cloudflare's WAF/CDN should onboard those applications to benefit from Layer 7 protection.