NETSCOUT Reveals Qualitative Shifts in DDoS Attack Sophistication, Infrastructure Capacity, and Threat Actor Capabilities
4.3.2026 12:05:00 CET | Business Wire | Press release
AI Adoption, coordinated botnets, and persistent hacktivists groups drove millions of attacks
NETSCOUT® SYSTEMS, INC. (NASDAQ: NTCT), today released its second half of the year 2025 Distributed Denial-of-Service (DDoS) Threat Intelligence Report, revealing sophisticated attacker collaboration, resilient botnets, and compromised IoT infrastructure that drove more than eight million DDoS attacks worldwide – some as large as 30 terabits per second (Tbps) – marking a new era of hyper-scale, coordinated threat activity that continues to outpace global takedown efforts. Meanwhile, the accelerating growth of DDoS-for-hire services is empowering a broader range of threat actors, intensifying operational risk to digitally connected organizations and enterprises.
Implications for security professionals extend far beyond volumetric concerns and include reconnaissance and adaptive evasion which challenge traditional defense paradigms. Organizations must match adversarial innovation with intelligent, autonomous defenses, or risk operational disruption at levels previously considered theoretical.
“Threat actors identify organizations that haven’t invested in the right defenses to stay ahead of sophisticated and coordinated DDoS attacks to take down critical infrastructure,” stated Richard Hummel, director, threat intelligence, NETSCOUT. “Traditional security defenses are no longer working, and with attackers hitting new attack size and complexity ceilings, implementing automated and proactive defenses has become a business-level risk mandate – not just a technical concern for security professionals.”
Key research findings include:
- Massive Attacks on a Global Scale – More than eight million attacks were identified across 203 countries and territories globally.
- Continued Use of Multi-Vector Attacks – approximately 42% of DDoS attacks employed two to five distinct attack vectors, with some adapting dynamically throughout the attack to complicate detection and mitigation.
- Outbound Attacks Impact Broadband and Mobile Services – Extensive direct-path attacks revealed that compromised IoT and customer-premises equipment can generate outbound floods exceeding 1 Tbps, creating liability, service, and reputational risk for broadband and mobile providers.
- Critical Infrastructure Targeted – High-value services such as NTP and DNS continue to face sustained attack pressure, emphasizing the need for resilient, globally distributed architectures to maintain service continuity.
- Threat Actors Scale Up Collaboration – A surge of more than 20,000 botnet-driven attacks in July 2025 exemplified how coordinated threat activity can rapidly overwhelm defenses and disrupt critical government, finance, and transportation services.
- Threat Actor Persistence – Despite international law enforcement dismantling multiple DDoS-for-hire platforms, hacktivist groups and botnets remain resilient, exerting increased pressure.
- AI Integration Accelerates Operations and Collaboration – AI has transitioned to an operational reality, with large language models (LLMs) on the dark web accelerating vulnerability exploitation and botnet expansion, and underground forums documenting a 219% increase in mentions of malicious AI tools. Groups like Keymous+ have demonstrated how partnerships between threat actors amplify attack power, with bandwidth increasing nearly fourfold.
NETSCOUT maps the DDoS landscape through passive, internet vantage points, providing unparalleled visibility into global attack trends. For more than 15 years, NETSCOUT has delivered trusted, consistent DDoS Intelligence based exclusively on directly observed, verifiable attack traffic. NETSCOUT does not aggregate multiple alerts or geographically distributed events into composite peak values, ensuring accuracy, repeatability, and true comparability across reporting periods. Peak metrics reflect single-second maximum bits-per-second (bps) and packets-per-second (pps) rates measured at defined mitigation and monitoring points.
NETSCOUT protects two-thirds of the routed IPv4 space, securing network edges that carried global peak traffic of over 800 Tbps, covering 376 industry verticals and 12,698 Autonomous System Numbers (ASNs) in the second half of 2025. It monitors tens of thousands of daily DDoS attacks by tracking multiple botnets and DDoS-for-hire services that leverage millions of abused or compromised devices.
Resources:
- Download the NETSCOUT’s DDoS Threat Intelligence Report H2 2025
- See real-time DDoS attack stats and insights by visiting NETSCOUT Cyber Threat Horizon
About NETSCOUT
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) protects the connected world from cyberattacks and performance and availability disruptions through its unique visibility platform and solutions powered by its pioneering deep packet inspection at scale technology. NETSCOUT serves the world’s largest enterprises, service providers, and public sector organizations. Learn more at www.netscout.com or follow @NETSCOUT on LinkedIn, X, or Facebook.
©2026 NETSCOUT SYSTEMS, INC. All rights reserved. Third-party trademarks mentioned are the property of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260304014007/en/
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Svante Acquires Carbon Dioxide Removal Project Developer, Carbon Alpha Corp.4.3.2026 16:00:00 CET | Press release
Svante acquires Carbon Alpha to accelerate commercial-scale carbon removal & expand its CCS/BECCS project development business in Western Canada. Acquisition adds the North Star BECCS Project, developed in partnership with the Meadow Lake Tribal Council, advancing the market for durable and verifiable CDR credits. The transaction strengthens Svante’s fully integrated carbon management platform, adding CO₂ storage expertise, a regional pipeline & a major geological storage hub. Svante Technologies Inc. (Svante), a leader in carbon management, and Calgary-based Carbon Alpha Corporation (Carbon Alpha) today announced that Svante has acquired Carbon Alpha and its related subsidiaries, including Carbon Alpha Development Corp. and its ownership interests in North Star Carbon Solutions Corp. and North Star Carbon Solutions Limited Partnership, a project developer for carbon capture and storage (CCS) in Western Canada. With this transaction, Carbon Alpha’s flagship North Star Bioenergy Carbon
Binarly Announces Leadership Transition as Enterprise Demand Accelerates for Supply-Chain Security4.3.2026 16:00:00 CET | Press release
Binarly, the industry leader in software and firmware supply‑chain security, today announced a leadership transition as the company enters its next phase of growth. Founder and current CEO Alex Matrosov has joined the company’s Board, and Gwenyth Castro has joined as Chief Executive Officer to scale global go-to-market and enterprise growth. Binarly developed its Transparency Platform on a unique, patented technology core designed to help the world’s largest enterprises identify and reduce third-party software risk across complex environments. The platform is trusted by organizations including Meta and Dell, among others. “We built Binarly to solve a problem the industry kept ignoring: you can’t secure what you can’t see,” said Alex Matrosov, Founder of Binarly. “Over the last five years, this team turned deep program analysis and vulnerability research into a platform trusted by some of the world’s most demanding enterprises. Now, as AI accelerates how software is built and shipped, t
Unleash Raises $35M Led by One Peak to Help Enterprises Ship AI-driven Software Faster, Safer, and Smarter4.3.2026 15:00:00 CET | Press release
Unleash, the open-source FeatureOps company, today announced a $35 million Series B financing led by One Peak, with participation from existing investors Spark Capital, Frontline Ventures, and Firstminute Capital. The new funding will be used to accelerate product innovation and global expansion as enterprises confront the opportunities and risks of AI-accelerated software delivery. AI has dramatically accelerated software development, creating a generational opportunity for anyone in an enterprise to turn ideas, prompts, and prototypes into applications. But AI has also outpaced the systems designed to control software delivery. DORA research shows that a 25% rise in AI adoption correlates with a 7% drop in software stability. Enterprises are shipping code 2-3x faster with AI, yet outages caused by uncontrolled feature rollouts and missing kill switches are costing businesses millions in lost revenue, prolonged customer downtime, and brand damage. FeatureOps is emerging as the missing
Capcom’s Resident Evil Requiem Surpasses 5 Million Units!4.3.2026 15:00:00 CET | Press release
– Worldwide acclaim contributed to strong sales – Capcom Co., Ltd. (TOKYO:9697) today announced that worldwide sales of Resident Evil Requiem, released on February 27, 2026, surpassed 5 million units. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260304446142/en/ Resident Evil Requiem Logo Resident Evil Requiem is the latest installment in the Resident Evil series, which celebrates its 30th anniversary this month. The title successfully elevated the essence of survival horror by heightening the interplay between intense fear and exhilarating action. Resident Evil Requiem was developed using RE ENGINE, Capcom’s proprietary game engine, which allowed the company to deliver visuals in photorealistic detail, including the characters’ skin, teary eyes, and flowing hair, as well as the translucency of light. In addition, the title offers a new game experience for a broad fanbase through multiple difficulty settings that accommoda
Siren Fusion 2026: The Convergence of People, Technology and Ideas4.3.2026 14:30:00 CET | Press release
An Invitation-Only Summit for Global Intelligence, National Security and Investigative Leaders Siren today announced Siren Fusion 2026, its inaugural global summit convening senior investigators, national security leaders and AI innovators for a high-trust forum on the future of investigative intelligence. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260304240853/en/ Siren Fusion 2026 is the convergence of people, technology and ideas, in Galway, Ireland. An invitation-only summit for global intelligence, national security and investigative leaders. Taking place in Galway, Ireland, Fusion is the deliberate convergence of people, technology and ideas within a national security frame. Structured as an educational and strategic forum rather than a conventional conference, Fusion 2026 focuses on the issues that now define the intelligence and law enforcement agenda: Geopolitical instability AI-driven investigative transformati
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom