2025 Q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults (opens in new tab)
Cloudflare’s 2025 DDoS report describes a dramatic escalation in both attack frequency and scale. DDoS attacks more than doubled to 47.1 million, while botnets such as Aisuru-Kimwolf launched unprecedented HTTP floods, including a record 31.4 Tbps attack. Cloudflare concludes that autonomous, adaptive mitigation is increasingly essential as attacks grow more frequent, larger, and more sophisticated.
Record Growth in DDoS Attacks
- Cloudflare mitigated 47.1 million DDoS attacks in 2025, a 121% increase from 2024 and a 236% increase since 2023.
- The network automatically mitigated an average of 5,376 attacks per hour:
- 3,925 network-layer attacks
- 1,451 HTTP attacks
- In Q4 2025, attacks increased 31% from the previous quarter and 58% year over year.
- Network-layer attacks accounted for 78% of Q4 activity.
Network-Layer Attacks More Than Triple
- Network-layer attacks rose from 11.4 million in 2024 to 34.4 million in 2025.
- An 18-day campaign in Q1 generated approximately 13.5 million attacks against Cloudflare infrastructure and Magic Transit customers.
- The campaign used multiple vectors, including:
- SYN floods
- Mirai-generated attacks
- SSDP amplification
- Cloudflare’s systems detected and mitigated the campaign automatically.
The Aisuru-Kimwolf “Night Before Christmas” Campaign
- Beginning December 19, 2025, the Aisuru-Kimwolf botnet attacked Cloudflare and its customers with HTTP floods exceeding 20 million requests per second.
- The botnet is estimated to contain 1–4 million malware-infected devices, primarily Android TVs.
- During the campaign, Cloudflare mitigated 902 hyper-volumetric attacks:
- 384 packet-intensive attacks
- 329 bit-intensive attacks
- 189 request-intensive attacks
- Average attack rates reached 3 billion packets per second, 4 Tbps, and 54 million requests per second.
- Maximum observed rates reached 9 Bpps, 24 Tbps, and 205 million requests per second.
Hyper-Volumetric Attacks Reach New Records
- Hyper-volumetric attacks increased 40% in Q4 compared with Q3.
- Attack sizes grew more than 700% compared with large attacks in late 2024.
- One attack reached 31.4 Tbps and lasted only 35 seconds.
- Other record-scale attacks reached 205 million requests per second.
- Telecommunications, service providers, and carriers were the primary targets, followed by gaming and generative AI services.
- Cloudflare infrastructure itself faced HTTP floods, DNS attacks, and UDP floods.
Most-Targeted Industries and Locations
- Telecommunications, service providers, and carriers became the most-attacked industry, replacing Information Technology & Services.
- Gambling and casinos ranked third, while gaming ranked fourth.
- Computer software and business services climbed significantly in the top-ten rankings.
- China, Germany, Brazil, and the United States remained among the most-attacked locations.
- Hong Kong rose 12 places to become the second most-attacked location.
- The United Kingdom climbed 36 places to rank sixth.
Cloudflare’s data shows that organizations should prepare for attacks that combine enormous volume with rapidly changing techniques. Automated, network-scale defenses capable of identifying and adapting to large botnets are becoming a necessity rather than an optional protection.