Cloudflare, the security, performance and reliability company helping to build a better Internet, has announced its 2025 Q3 DDoS report. This report includes insights and trends about the DDoS threat landscape as observed across the global Cloudflare network, which is one of the largest in the world.
Key findings
- The Aisuru botnet unleashed hyper-volumetric attacks at unprecedented scale: With an estimated 1–4 million infected hosts, the Aisuru botnet routinely launched hyper-volumetric DDoS attacks exceeding 1 terabit per second (Tbps) and 1 billion packets per second (Bpps), with attacks surging 54% quarter-on-quarter.
- AI companies capture the attention of attackers: DDoS attack traffic against AI companies surged by as much as 347% month-on-month in September 2025, as public concern and regulatory scrutiny of AI increases.
- Geopolitical events continue to be reflected in cyberspace: Escalating EU–China trade tensions over rare earth minerals and EV tariffs coincide with a significant increase in DDoS attacks against the mining, minerals and metals industry, as well as the automotive industry.
DDoS attacks in numbers
So far in 2025, with a full quarter still remaining, Cloudflare has already mitigated 36.2 million DDoS attacks — equivalent to 170% of the total mitigated throughout 2024.
In Q3 2025 alone, Cloudflare automatically detected and mitigated 8.3 million DDoS attacks, representing a 15% increase quarter-on-quarter and a 40% increase year-on-year.
Network-layer DDoS attacks accounted for 71% of all DDoS attacks in Q3 2025 (5.9 million), increasing by 87% quarter-on-quarter and 95% year-on-year.
HTTP DDoS attacks accounted for 29% (2.4 million), decreasing by 41% quarter-on-quarter and 17% year-on-year.
Attack characteristics
While the majority of DDoS attacks are relatively small, in Q3 the volume of attacks exceeding 100 million packets per second (Mpps) increased by 189% quarter-on-quarter.
Attacks exceeding 1 Tbps increased by 227% quarter-on-quarter. On the HTTP layer, four in every 100 attacks exceeded 1 million requests per second.
Most attacks — 71% of HTTP DDoS and 89% of network-layer DDoS — end in under 10 minutes. This is too fast for any human or on-demand service to react. Even very short attacks can cause severe disruption, with recovery taking much longer than the attack itself.
Top attack sources
- Seven of the top ten attack-originating locations were in Asia.
- Indonesia remained the largest source globally, maintaining its number-one position for a full year.
Top attacked industries
Top 10 attacked sectors in Q3 2025 included: Information Technology & Services, Telecommunications, Gambling & Casinos, Gaming, Internet, Automotive, Banking & Financial Services, Retail, Consumer Electronics, and Media, Production & Publishing.
- Rare earth minerals under fire: DDoS attacks against the mining, minerals and metals industry surged, pushing the sector up 24 places to become the 49th most attacked worldwide.
- Automotive overtakes others: The automotive industry saw the largest surge, jumping 62 places to rank sixth globally.
- Cybersecurity targeted: The cybersecurity industry rose 17 places, ranking 13th.
DDoS attacks against AI surge by 347%
In September 2025, Cloudflare observed month-on-month spikes as high as 347% in HTTP DDoS attack traffic targeting generative AI companies.
Top attacked locations
In Q3 2025:
- China remained the most attacked country.
- Turkey ranked second, Germany third.
- The United States rose 11 places to fifth.
- The Philippines jumped 20 places — the most significant increase in the top 10.
Attack vectors
Network-layer DDoS attacks
- UDP floods, partly fuelled by Aisuru, rose 231% quarter-on-quarter, becoming the leading vector.
- DNS floods ranked second, SYN floods third and ICMP floods fourth — together making up more than half of all network-layer attacks.
- Mirai variants remain active: nearly 2% of all network-layer attacks were linked to Mirai permutations.

HTTP DDoS attacks
- Nearly 70% originated from botnets already known to Cloudflare.
- Around 20% came from fake or headless browsers or included suspicious HTTP attributes.
- The remaining ~10% included generic floods, unusual requests, cache-busting attacks and login-endpoint targeting.
Commentary
Bashar Bashaireh, Area VP Middle East, Türkiye and North Africa at Cloudflare, said: “What the Q3 2025 data clearly shows is that DDoS activity is increasingly tied to geopolitical tension, critical infrastructure and high-growth sectors such as AI and telecommunications. Across the Middle East, where connectivity underpins economic diversification and smart-nation initiatives, these findings are a timely reminder that legacy defences are no longer sufficient against today’s botnet-driven attacks.”


