NETSCOUT® SYSTEMS, INC., has published the latter half of 2025 Distributed Denial-of-Service (DDoS) Threat Intelligence Report, unveiling the landscape of cyber threats that triggered over eight million DDoS attacks worldwide.
Some attacks reached a staggering magnitude of 30 terabits per second (Tbps), reflecting a surge in coordinated threat activities that are outpacing global deterrence efforts. The report highlights the expanding landscape of DDoS-for-hire services, which are empowering a wider spectrum of threat actors and heightening risks for digitally connected businesses.
Challenges Facing Security Paradigms
The implications for security professionals extend well beyond purely volumetric attack concerns as threats now include reconnaissance tactics and adaptive evasion that undermine traditional defense systems. Organizations are urged to innovate their defenses through intelligent, autonomous solutions or face risks of severe operational disruption.
Richard Hummel, director of threat intelligence at NETSCOUT, noted, "Threat actors identify organizations that haven’t invested in the right defences to stay ahead of sophisticated and coordinated DDoS attacks to take down critical infrastructure." He added that the emergence of larger and more complex attacks necessitates the implementation of automated and proactive defense measures as a fundamental business-risk requirement.
Key Findings on Global DDoS Activity
The research uncovered several critical insights:
- Global Scale of Attacks: More than eight million attacks spanned 203 countries and territories.
- Multi-Vector Approach: Around 42% of attacks utilized two to five different vectors, with some adapting during assaults to complicate countermeasures.
- Impact on Services: Direct-path attacks showed compromised IoT and customer-premises equipment generating outbound floods exceeding 1 Tbps, posing significant risks to broadband and mobile service providers.
- Infrastructure Targeting: Critical services like NTP and DNS are under sustained attack pressure, highlighting the need for robust, distributed architectures to ensure service continuity.
- Collaboration Among Threat Actors: In July 2025, over 20,000 botnet-driven attacks on government, finance, and transportation services highlighted their ability to overwhelm defences through coordination.
- Resilient Attacker Networks: Despite dismantling efforts against DDoS-for-hire platforms, resistant hacktivist groups and botnets maintain pressure.
- AI in Operations: AI, integrated into threat operations, accelerated vulnerability exploitation and botnet growth as indicated by a 219% rise in references to malicious AI tools within dark web communities.
Insight into DDoS Trends
NETSCOUT safeguarded two-thirds of the routed IPv4 space, covering industry sectors
NETSCOUT offers comprehensive mapping of the DDoS landscape through passive internet vantage points, providing unmatched visibility into global attack patterns.
For over 15 years, NETSCOUT has offered trusted DDoS intelligence based on directly observed attack traffic rather than aggregated alerts, ensuring precision and comparability across time periods. Their peak metrics illustrate single-second maximum bits-per-second (bps) and packets-per-second (pps) rates measured at specific mitigation and monitoring points.
In the second half of 2025, NETSCOUT safeguarded two-thirds of the routed IPv4 space, covering industry sectors and tracking tens of thousands of daily DDoS attacks. The company monitors numerous botnets and DDoS-for-hire services that exploit millions of infected devices worldwide.
NETSCOUT® SYSTEMS, INC., releases its second half of the year 2025 Distributed Denial-of-Service (DDoS) Threat Intelligence Report, revealing sophisticated attacker collaboration, resilient botnets, and compromised IoT infrastructure that drove more than eight million DDoS attacks worldwide – some as large as 30 terabits per second (Tbps) – marking a new era of hyper-scale, coordinated threat activity that continues to outpace global takedown efforts.
Meanwhile, the accelerating growth of DDoS-for-hire services is empowering a broader range of threat actors, intensifying operational risk to digitally connected organizations and enterprises.
Traditional defense paradigms
Implications for security professionals extend far beyond volumetric concerns and include reconnaissance and adaptive evasion which challenge traditional defense paradigms. Organizations must match adversarial innovation with intelligent, autonomous defences, or risk operational disruption at levels previously considered theoretical.
“Threat actors identify organizations that haven’t invested in the right defences to stay ahead of sophisticated and coordinated DDoS attacks to take down critical infrastructure,” stated Richard Hummel, director, threat intelligence, NETSCOUT. “Traditional security defences are no longer working, and with attackers hitting new attack size and complexity ceilings, implementing automated and proactive defences has become a business-level risk mandate – not just a technical concern for security professionals.”
Customer-premises equipment
Key research findings include:
- Massive attacks on a global scale – More than eight million attacks were identified across 203 countries and territories globally.
- Continued use of multi-vector attacks – Approximately 42 percent of DDoS attacks employed two to five distinct attack vectors, with some adapting dynamically throughout the attack to complicate detection and mitigation.
- Outbound attacks impact broadband and mobile services – Extensive direct-path attacks revealed that compromised IoT and customer-premises equipment can generate outbound floods exceeding 1 Tbps, creating liability, service, and reputational risk for broadband and mobile providers.
- Critical infrastructure targeted – High value services such as NTP and DNS continue to face sustained attack pressure, emphasising the need for resilient, globally distributed architectures to maintain service continuity.
- Threat actors scale up collaboration – A surge of more than 20,000 botnet-driven attacks in July 2025 exemplified how coordinated threat activity can rapidly overwhelm defences and disrupt critical government, finance, and transportation services.
- Threat actor persistence – Despite international law enforcement dismantling multiple DDoS-for-hire platforms, hacktivist groups, and botnets remain resilient, exerting increased pressure.
- AI integration accelerates operations and collaboration – AI has transitioned to an operational reality, with large language models (LLMs) on the dark web accelerating vulnerability exploitation and botnet expansion, and underground forums documenting a 219 percent increase in mentions of malicious AI tools. Groups like Keymous+ have demonstrated how partnerships between threat actors amplify attack power, with bandwidth increasing nearly fourfold.
Providing unparalleled visibility
NETSCOUT maps the DDoS landscape through passive, internet vantage points, providing unparalleled visibility into global attack trends.
For more than 15 years, NETSCOUT has delivered trusted, consistent DDoS Intelligence based exclusively on directly observed, verifiable attack traffic. NETSCOUT does not aggregate multiple alerts or geographically distributed events into composite peak values, ensuring accuracy, repeatability, and true comparability across reporting periods. Peak metrics reflect single-second maximum bits-per-second (bps) and packets-per-second (pps) rates measured at defined mitigation and monitoring points.
NETSCOUT protects two-thirds of the routed IPv4 space, securing network edges that carried global peak traffic of over 800 Tbps, covering 376 industry verticals and 12,698 Autonomous System Numbers (ASNs) in the second half of 2025. It monitors tens of thousands of daily DDoS attacks by tracking multiple botnets and DDoS-for-hire services that leverage millions of abused or compromised devices.