>samit_hota
Back to security news

Security News · SN-2026-378

HIGHMITIGATED

Volumetric DDoS Attacks Over 1 Tbps Surged Fivefold in Q2

Affected: Web Infrastructure · Media & Publishing · Government Infrastructure · Authoritative DNS

Samit Hota·
#news#ddos#ddos

DDoS attacks exceeding 1 Tbps saw an unprecedented 519% quarter-over-quarter surge in the second quarter of the year, driven by expanding botnet infrastructure and shifting reflection techniques. In a report presented at the Black Hat security conference, web infrastructure provider Cloudflare disclosed that its network mitigated over 800 network-layer distributed denial-of-service (DDoS) events topping the terabit-per-second threshold in Q2, compared to just 130 such incidents recorded in Q1. Across the entire first half of the year, total attack traffic reached 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests, highlighting a persistent rise in both volumetric saturation and application-layer disruption.

The exponential increase in multi-terabit attacks marks a distinct shift in adversary capabilities, with threat actors deploying compromised IoT fleets and high-bandwidth cloud instances to launch overwhelming volumetric floods.

A Fivefold Spike in Terabit-Scale Volumetric Attacks

While small-scale volumetric attacks remain the baseline statistical norm—with 96.62% of network-layer attacks staying below 50 Mbps and 90.6% resolving within 10 minutes—the upper band of attack magnitude has expanded dramatically. Attacks ranging between 500 Gbps and 1 Tbps increased by 143% quarter-over-quarter, while mid-tier floods between 100 Gbps and 500 Gbps grew by 105%. Long-duration attacks lasting longer than three hours also saw a slight uptick, rising from 0.387% of all observed incidents in Q1 to 0.828% in Q2.

The pinnacle of this quarterly surge was a record-breaking multi-vector attack that peaked at 31.4 Tbps and 200 million requests per second (RPS). The attack was launched by the Aisuru/Kimwolf botnet, a large-scale botnet composed of compromised devices and cloud workloads. Overall, network-layer DDoS incidents rose 31.2% quarter-over-quarter (from 10.04 million to 13.17 million), while application-layer malicious HTTP request volume grew 32.4% (from 12.75 trillion to 16.89 trillion requests). Peak combined activity occurred in April, generating 6.46 trillion HTTP DDoS requests and 165 petabytes (PB) of network-layer flood volume before dropping off in May and June.

Amplification Shifts: CLDAP and DNS Floods Take Center Stage

The mechanics behind these high-volume floods reveal a heavy reliance on UDP-based reflection and amplification vectors, which allow attackers to spoof target IP addresses and generate asymmetric response payloads from unsecured third-party servers.

In Q2, threat actors shifted heavily toward DNS-based vectors and Connectionless Lightweight Directory Access Protocol (CLDAP) reflection:

  • DNS Floods: DNS-based attacks accounted for 40% of all network-layer DDoS attacks in Q2, up from 25.7% in Q1. Combined with DNS amplification, DNS-related techniques represented 34.3% of all network-layer attacks in the first half of the year.
  • CLDAP Amplification: Reflection floods leveraging CLDAP surged by an extraordinary 881.9% quarter-over-quarter. Running over UDP port 389, unauthenticated CLDAP servers yield amplification factors up to 70x, making them ideal mechanisms for generating massive volumetric spikes without requiring proportionate botnet bandwidth.
  • UDP Floods: Standard UDP floods remained the second most prevalent attack vector in Q2, accounting for 14.06% of network-layer incidents.

The temporary decline in DDoS volume following the April peak was largely credited to law enforcement intervention. Operation PowerOFF, an international law enforcement campaign targeting commercial DDoS-for-hire (booter/stresser) infrastructure, resulted in four arrests, the seizure of 53 booter domains, and formal warning notices issued to over 75,000 registered users of illegal stresser services.

Targeted Sectors and the Real-World Blast Radius

The Media, Production, and Publishing sector bore the largest brunt of targeted application-layer activity in H1, receiving 14.2% of all mitigated malicious HTTP DDoS requests. Public sector targets also experienced a pronounced spike in targeting driven by geopolitical friction, particularly hacktivism connected to US-Israeli military operations against Iran.

For enterprise environments, the blast radius of terabit-scale DDoS attacks extends far beyond simple web server unresponsiveness:

  1. Upstream Transit Saturation: Attacks exceeding 1 Tbps saturate carrier-grade transit links, peering connections, and edge router forwarding buffers long before traffic reaches on-premises firewalls or local reverse proxies.
  2. Infrastructure Collateral Damage: Massive UDP and DNS amplification attacks exhaust state tables in perimeter security appliances, causing cascading outages for co-located enterprise services, VPN gateways, and internal voice/VoIP infrastructure.
  3. Authoritative DNS Starvation: High-volume DNS floods targeted at enterprise DNS infrastructure compromise domain resolution entirely. When authoritative DNS servers fail under load, all public-facing services—including email delivery (SMTP), API endpoints, and SaaS authentication workflows—become unreachable globally regardless of whether web servers remain operational.

Defense and Mitigation Requirements

Defending against multi-terabit volumetric floods and rapid reflection shifts requires strict perimeter hygiene combined with cloud-scrubbing capabilities.

  • Disable Open CLDAP/Directory Services: Ensure LDAP and CLDAP services on UDP port 389 are strictly bound to internal networks and blocked from answering public queries at the external firewall.
  • Implement DNS Response Rate Limiting (RRL): Organizations hosting authoritative DNS infrastructure must enforce RRL and rate-limiting policies on incoming UDP/53 queries to minimize their susceptibility to becoming reflection reflectors or flood victims.
  • Enforce Source Address Validation: Network operators must strictly enforce Source Address Validation (BCP 38 / RFC 2827) on egress and ingress interfaces to prevent IP address spoofing across regional transit links.
  • Leverage BGP Flowspec and Cloud Scrubbing: Terabit-scale attacks cannot be mitigated locally. Enterprise networks facing sustained volumetric targeting should integrate cloud-based DDoS scrubbing services operating via Anycast routing and BGP Flowspec (RFC 5575) rules to filter volumetric traffic at the ISP carrier edge.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call