cloudflare

2025 Q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults (opens in new tab)

Cloudflare’s 2025 DDoS report describes a dramatic escalation in both attack frequency and scale. DDoS attacks more than doubled to 47.1 million, while botnets such as Aisuru-Kimwolf launched unprecedented HTTP floods, including a record 31.4 Tbps attack. Cloudflare concludes that autonomous, adaptive mitigation is increasingly essential as attacks grow more frequent, larger, and more sophisticated.

Record Growth in DDoS Attacks

  • Cloudflare mitigated 47.1 million DDoS attacks in 2025, a 121% increase from 2024 and a 236% increase since 2023.
  • The network automatically mitigated an average of 5,376 attacks per hour:
    • 3,925 network-layer attacks
    • 1,451 HTTP attacks
  • In Q4 2025, attacks increased 31% from the previous quarter and 58% year over year.
  • Network-layer attacks accounted for 78% of Q4 activity.

Network-Layer Attacks More Than Triple

  • Network-layer attacks rose from 11.4 million in 2024 to 34.4 million in 2025.
  • An 18-day campaign in Q1 generated approximately 13.5 million attacks against Cloudflare infrastructure and Magic Transit customers.
  • The campaign used multiple vectors, including:
    • SYN floods
    • Mirai-generated attacks
    • SSDP amplification
  • Cloudflare’s systems detected and mitigated the campaign automatically.

The Aisuru-Kimwolf “Night Before Christmas” Campaign

  • Beginning December 19, 2025, the Aisuru-Kimwolf botnet attacked Cloudflare and its customers with HTTP floods exceeding 20 million requests per second.
  • The botnet is estimated to contain 1–4 million malware-infected devices, primarily Android TVs.
  • During the campaign, Cloudflare mitigated 902 hyper-volumetric attacks:
    • 384 packet-intensive attacks
    • 329 bit-intensive attacks
    • 189 request-intensive attacks
  • Average attack rates reached 3 billion packets per second, 4 Tbps, and 54 million requests per second.
  • Maximum observed rates reached 9 Bpps, 24 Tbps, and 205 million requests per second.

Hyper-Volumetric Attacks Reach New Records

  • Hyper-volumetric attacks increased 40% in Q4 compared with Q3.
  • Attack sizes grew more than 700% compared with large attacks in late 2024.
  • One attack reached 31.4 Tbps and lasted only 35 seconds.
  • Other record-scale attacks reached 205 million requests per second.
  • Telecommunications, service providers, and carriers were the primary targets, followed by gaming and generative AI services.
  • Cloudflare infrastructure itself faced HTTP floods, DNS attacks, and UDP floods.

Most-Targeted Industries and Locations

  • Telecommunications, service providers, and carriers became the most-attacked industry, replacing Information Technology & Services.
  • Gambling and casinos ranked third, while gaming ranked fourth.
  • Computer software and business services climbed significantly in the top-ten rankings.
  • China, Germany, Brazil, and the United States remained among the most-attacked locations.
  • Hong Kong rose 12 places to become the second most-attacked location.
  • The United Kingdom climbed 36 places to rank sixth.

Cloudflare’s data shows that organizations should prepare for attacks that combine enormous volume with rapidly changing techniques. Automated, network-scale defenses capable of identifying and adapting to large botnets are becoming a necessity rather than an optional protection.