Cloudflare's 2024 Q4 DDoS Report: A Record-Breaking Quarter

Cloudflare's latest DDoS Threat Report, released for Q4 2024, reveals a threat landscape defined by unprecedented scale and sophistication. The network provider, which now protects roughly 20% of all websites, reported a substantial surge in attack volume, culminating in the largest DDoS attack ever publicly recorded.

During 2024, Cloudflare's autonomous defense systems neutralized approximately 21.3 million DDoS attacks, a 53% increase from the previous year. This translates to an average of 4,870 attacks blocked every hour. The fourth quarter alone contributed significantly to this total, with 6.9 million attacks mitigated—a 16% rise quarter-over-quarter and an 83% increase year-over-year.

The Largest Attack on Record

The peak of this activity came during the week of Halloween 2024, when Cloudflare detected and mitigated a hyper-volumetric DDoS attack that reached 5.6 Terabits per second (Tbps). This event stands as the largest attack ever reported. In Q4 alone, more than 420 attacks exceeded rates of 1 billion packets per second or 1 Tbps, and the number of attacks surpassing 1 Tbps grew by a staggering 1,885% quarter-over-quarter.

BLOG-2655 hero image

Anatomy of HTTP DDoS Attacks

A slight majority (51%) of Q4's attacks targeted the HTTP layer, with the remaining 49% being network-layer (L3/4) assaults. Among HTTP attacks, a significant portion—73%—originated from known botnets. An additional 11% were designed to mimic legitimate browsers, 10% exhibited suspicious HTTP attributes, and the remaining 8% were generic HTTP floods, volumetric cache busting, or attacks on login endpoints.

An analysis of the user agents used in these attacks reveals a curious trend. Threat actors favored older, widely-compatible versions of Chrome (versions 118 to 129) rather than the current stable version 132. More telling was the HITV_ST_PLATFORM user agent, which appeared in DDoS traffic 99.9% of the time. This agent is associated with smart TVs and set-top boxes, indicating that compromised connected devices are being actively used in botnet attacks. Other common agents included hackney, an Erlang HTTP client library with a 93% DDoS association rate, as well as uTorrent, Go-http-client, and fasthttp.

The report also flagged HTTP methods and paths that are disproportionate indicators of malicious activity. While GET requests dominate legitimate traffic (70%), a surprising 14% of HEAD method requests were part of DDoS attacks, despite constituting less than 1% of legitimate traffic. Similarly, the /wp-admin/ path—the administrative dashboard for WordPress—was targeted by DDoS traffic 98% of the time.

Network-Layer Attacks and Emerging Threats

At the network layer, SYN floods were the dominant attack vector, accounting for 38% of all L3/4 attacks. This was followed by DNS flood attacks (16%) and UDP floods (14%). Attacks from variants of the Mirai botnet saw a 131% increase quarter-over-quarter and were responsible for the record-breaking 5.6 Tbps attack mentioned earlier.

Beyond these established methods, Cloudflare observed significant growth in other attack vectors. Memcached DDoS attacks, which exploit a database caching system to amplify traffic by up to 51,200 times, surged by 314% quarter-over-quarter. Attacks leveraging the BitTorrent peer-to-peer file-sharing protocol also saw a massive spike, increasing by 304%.

The Expanding Attack Surface

The scale of Cloudflare's mitigation efforts is supported by its immense network infrastructure, which has grown to 321 Tbps in capacity and spans 330 cities globally—a 65% increase since 2020. This extensive vantage point is crucial for identifying and blocking attacks before they can cause disruption. The trends from Q4, particularly the rise of hyper-volumetric attacks exceeding 1 Tbps and the repurposing of everyday devices like smart TVs, underscore the increasing complexity and firepower of modern DDoS campaigns. The findings serve as a reminder that securing all internet-connected devices is critical to mitigating the risk of these ever-evolving threats.

A 5.6 Tbps record-breaker

On October 29, Cloudflare's autonomous defenses intercepted a 5.6 Tbps UDP DDoS attack targeting a Magic Transit customer, an Internet service provider in Eastern Asia. The attack, launched by a Mirai-variant botnet, lasted 80 seconds and originated from over 13,000 IoT devices. Detection and mitigation were entirely automated—no human intervention, no alerts, and no performance degradation for the customer. While the total source IP count was roughly 13,000, the average was about 5,500 unique IP addresses per second, with each IP contributing around 1 Gbps on average. No single source exceeded 8 Gbps.

image16

Hyper-volumetric attack growth

The record-breaking event capped a quarter marked by a sharp rise in hyper-volumetric network-layer attacks. Compared to 2024 Q3, attacks exceeding 1 Tbps grew by 1,885% quarter-over-quarter, while those surpassing 100 million packets per second (pps) increased by 175%. Among the latter, 16% also exceeded 1 billion pps.

image6

Most attacks remain small by volume. Some 63% of HTTP DDoS attacks stayed below 50,000 requests per second, while only 3% exceeded 100 million requests per second. On the network layer, 93% of attacks were under 500 Mbps and 87% under 50,000 pps. Durations are similarly short: 72% of HTTP attacks ended within ten minutes, and 22% lasted over an hour. For network-layer attacks, 91% ended within ten minutes and just 2% exceeded one hour. These brief, sharp bursts make human response impractical, reinforcing the need for always-on, inline automated mitigation.

image11

Where attacks originate

Indonesia remained the top global source of DDoS traffic for a second consecutive quarter. Hong Kong moved up five spots to second place, and Singapore advanced three to third. For HTTP attacks, source mapping uses non-spoofable IP addresses; for Layer 3/4 attacks, Cloudflare maps the data center locations where packets were ingested. Attribution for source countries and networks relies on the vendor's global footprint spanning over 330 cities.

image2

At the network level, German provider Hetzner (AS24940) led as the top autonomous system for HTTP DDoS traffic, accounting for nearly 5% of all blocked HTTP DDoS requests. It was followed by US-based Digital Ocean (AS14061) and France-based OVH (AS16276). Network operators struggling to identify malicious actors on their infrastructure can use Cloudflare's free DDoS Botnet threat intelligence feed, which lists IP addresses observed participating in attacks.

image12

Actors and extortion

Among surveyed Cloudflare customers who identified their attackers, competitors topped the list at 40%. State-level or state-sponsored actors were cited by 17%, with a similar share pointing to disgruntled users or customers. Extortionists accounted for 14%, self-inflicted attacks 7%, hacktivism 2%, and former employees 2%.

Ransom DDoS attacks followed their expected seasonal pattern in Q4. With increased online shopping, travel, and holiday activity, disruption becomes more lucrative. In Q4, 12% of targeted customers reported ransom threats—a 78% quarter-over-quarter increase and 25% year-over-year growth. Monthly reports climbed from 10% in October to 13% in November and 14% in December; the year's peak was May.

image17

Targets and industries

China remained the most attacked country, based on customer billing locations. The Philippines appeared in the top ten for the first time, in second place, while Taiwan jumped seven spots to third.

image5

By industry, Telecommunications, Service Providers and Carriers rose from third to first, followed by the Internet industry and Marketing and Advertising. Banking & Financial Services fell hardest, dropping seven places from the top spot in Q3 to eighth in Q4.

image7

Defense implications

The Q4 surge in hyper-volumetric attacks, capped by the 5.6 Tbps record, underscores the limits of capacity-bound cloud mitigation and on-premise appliances. Powerful botnets and geopolitical factors have widened the target landscape, while rising ransom DDoS activity adds another layer of risk. Organizations that deploy proactive, automated protection before an incident fare better than those reacting after the fact. Cloudflare's approach relies on its 321 Tbps network spanning 330 cities, delivering unmetered, unlimited DDoS protection regardless of attack size, duration, or frequency.