MA-NETSCOUT-SYSTEMS
NETSCOUT SYSTEMS, INC., (NASDAQ: NTCT) today announced findings from its bi-annual Threat Intelligence Report . During the second half of 2021, cybercriminals launched approximately 4.4 million Distributed Denial of Service (DDoS) attacks, bringing the total number of DDoS attacks in 2021 to 9.75 million. These attacks represent a 3% decrease from the record number set during the height of the pandemic but continue at a pace that's 14% above pre-pandemic levels.
The report details how the second half of 2021 established high-powered botnet armies and rebalanced the scales between volumetric and direct-path (non-spoofed) attacks, creating more sophisticated operating procedures for attackers and adding new tactics, techniques, and methods to their arsenals.
“While it may be tempting to look at the decrease in overall attacks as threat actors scaling back their efforts, we saw significantly higher activity compared to pre-pandemic levels,” said Richard Hummel, threat intelligence lead, NETSCOUT. “The reality is that attackers are constantly innovating and adapting new techniques, including the use of server-class botnets, DDoS-for-Hire services, and increased used direct-path attacks that continually perpetuate the advancement of the threat landscape.”
Other key findings from the NETSCOUT 2H2021 Threat Intelligence Report include:
- DDoS Extortion and Ransomware Operations are on the rise. Three high-profile DDoS extortion campaigns simultaneously operating is a new high. Ransomware gangs including Avaddon, REvil, BlackCat, AvosLocker, and Suncrypt were observed using DDoS to extort victims. Because of their success, ransomware groups have DDoS extortion operators masquerading as affiliates like the recent REvil DDoS Extortion campaign.
- VOIP Services were Targets of DDoS Extortion. Worldwide DDoS extortion attack campaigns from the REvil copycat were waged against several VOIP services providers. One VOIP service provider reported $9M-$12M in revenue loss due to DDoS attacks.
- DDoS-for-Hire services made attacks easy to launch. NETSCOUT examined 19 DDoS-for-Hire services and their capabilities that eliminate the technical requirements and cost of launching massive DDoS attacks. When combined, they offer more than 200 different attack types.
- APAC attacks increased by 7% as other regions subsided . Amid ongoing geopolitical tensions in China, Hong Kong, and Taiwan, the Asia-Pacific region saw the most significant increase in attacks year over year compared to other regions.
- Server-class botnet armies arrived. Cybercriminals have not only increased the number of Internet-of-Things (IoT) botnets but have also conscripted high-powered servers and high-capacity network devices, as seen with the GitMirai, Meris, and Dvinis botnets.
- Direct-path attacks are gaining in popularity . Adversaries inundated organizations with TCP- and UDP-based floods, otherwise known as direct-path or non-spoofed attacks. Meanwhile, a decrease in some amplification attacks drove down the number of total attacks.
- Attackers targeted select industries . Those hardest hit include software publishers (606% increase), insurance agencies and brokers (257% increase), computer manufacturers (162% increase), and colleges, universities, and professional schools (102% increase)
- The fastest DDoS attack recorded a 107% year-over-year increase. Using DNS, DNS amplification, ICMP, TCP, ACK, TCP RST, and TCP SYN vectors, the multi-vector attack against a target in Russia recorded 453 Mpps.
NETSCOUT's Threat Intelligence Report covers the latest trends and activities in the DDoS threat landscape. It covers data captured from NETSCOUT's Active Level Threat Analysis System (ATLAS™) coupled with insights from NETSCOUT's ATLAS Security Engineering & Response Team.
The visibility and insights compiled from the global DDOS attack data, which is represented in the Threat Intelligence Report and can be seen in the Omnis Threat Horizon portal, fuel the ATLAS Intelligence Feed used across NETSCOUT's Omnis security portfolio to detect and block threat activity for enterprises and service providers worldwide.
Visit our interactive website for more information on NETSCOUT's semi-annual Threat Intelligence Report. You can also find us on Facebook , LinkedIn , and Twitter for threat updates and the latest trends and insights.
About NETSCOUT
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) helps assure digital business services against security, availability, and performance disruptions. Our market and technology leadership stems from combining our patented smart data technology with smart analytics. We provide real-time, pervasive visibility and insights customers need to accelerate and secure their digital transformation. Omnis® Cyber Intelligence delivers the fastest and most scalable network security solution available on the market. NETSCOUT nGenius® service assurance solutions provide real-time, contextual analysis of service, network, and application performance. And Arbor® Smart DDoS Protection by NETSCOUT products help protect against attacks that threaten availability and advanced threats that infiltrate networks to steal critical business assets. To learn more about improving service, network, and application performance in physical or virtual data centers or in the cloud, and how NETSCOUT's security and performance solutions can help you move forward with confidence, visit www.netscout.com or follow @NETSCOUT on Twitter, Facebook, or LinkedIn.
©2022 NETSCOUT SYSTEMS, INC. All rights reserved. NETSCOUT, the NETSCOUT logo, Guardians of the Connected World, Adaptive Service Intelligence, Arbor, ATLAS, Cyber Threat Horizon, InfiniStream, nGenius, nGeniusONE, and Omnis are registered trademarks or trademarks of NETSCOUT SYSTEMS, INC., and/or its subsidiaries and/or affiliates in the USA and/or other countries. Third-party trademarks mentioned are the property of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220322005111/en/
Social Media:
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Aspect Expands Cloud Workforce Experience and Developer Tools to New Regions and Introduces AI-Powered Forecasting18.11.2025 15:00:00 CET | Press release
New release brings predictive intelligence, regional expansion, and enhanced employee performance tools to contact center operations. Aspect, a leading provider of cloud-based workforce management solutions, today announced its Q4 2025 product release, delivering AI-powered predictive forecasting for call volume, regional expansion into Canada, UK, and Europe, and new employee performance capabilities. The release represents a significant step forward in Aspect's mission to empower workforces with intelligent, modern tools that drive operational efficiency and employee engagement. AI-Driven Forecasting Brings New Precision and Agility to Workforce Planning The enhanced Forecast Dashboard introduces Predictive Forecasting with built-in AI intelligence. This new feature automatically generates four-week call volume forecasts that refresh daily, eliminating manual setup and enabling planners to make faster, more confident scheduling decisions. By analyzing historical data with advanced al
FireMon Expands Zero Trust Microsegmentation Coverage with Illumio, VMware NSX, and Zscaler18.11.2025 15:00:00 CET | Press release
Deep Illumio integration and continued VMware NSX and Zscaler support, security teams can now operationalize Zero Trust at enterprise scale. FireMon, the leading network security and firewall policy management company, today detailed expanded support for Zero Trust microsegmentation across hybrid environments, including a deeper integration with Illumio and continued coverage for VMware NSX and Zscaler. By normalizing, analyzing, and continuously validating segmentation intent across network, virtual, and host enforcement points, FireMon helps security teams operationalize Zero Trust at enterprise scale. “The future isn’t more consoles,” said Jody Brazil, CEO of FireMon. “It’s one policy playbook that proves control efficacy every day and the evidence to back it up.” Organizations using FireMon to unify segmentation and firewall governance report measurable outcomes, including up to a 90% reduction in compliance reporting time through consolidated policy data and faster validation and
Silicon Labs Partners with Rimini Street to Build a Future-Ready SAP Strategy18.11.2025 15:00:00 CET | Press release
Multi-year strategic partnership empowers Silicon Labs to maximize SAP ECC 6.0 value, accelerate transformation and avoid costly upgrades and disruption Rimini Street, Inc. (Nasdaq: RMNI), a global provider of end-to-end enterprise software support, managed services and Agentic AI ERP innovation solutions, and the leading third-party support provider for Oracle, SAP and VMware software, today announced Silicon Labs has selected Rimini Street as its strategic partner to maximize the value of its SAP ECC 6.0 investment. This collaboration provides the U.S.-based semiconductor manufacturer with long-term SAP maintenance and professional services to accelerate modernization without costly upgrades or business disruption. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251118277544/en/ Silicon Labs Partners with Rimini Street to Build a Future-Ready SAP Strategy Partnership Reduces Technical Debt and Accelerates Modernization Sili
Gurobi Releases Version 13.0 with Improved Performance and New Solving Capabilities18.11.2025 15:00:00 CET | Press release
Users can expect faster solves, new nonlinear capabilities, PDHG with GPU acceleration, and Kubernetes autoscaling. Gurobi Optimization, LLC, the leader in decision intelligence technology, is pleased to announce the release of Gurobi 13.0. This latest version represents a significant advancement in Gurobi’s mission to help organizations tackle increasingly complex optimization challenges with greater speed and flexibility. Version 13.0 introduces performance improvements across core model types, new algorithm support for large-scale and nonlinear problems, GPU acceleration, and expanded cloud-native functionality. “Today’s organizations face optimization challenges that are often domain-specific and more complex than ever,” said Dr. Oliver Bastert, CTO, Gurobi Optimization. “With Gurobi 13.0, we’re extending our technology to handle even larger models and more nonlinear problem types—delivering measurable speed-ups and greater flexibility across a wide range of applications.” Enhancem
Core42 “Maximus-384” Cluster Secures Top 20 Ranking on the Global TOP500 Supercomputers List18.11.2025 14:24:00 CET | Press release
Core42, A G42 Company, secures #20 position with its AMD Instinct MI300X GPU cluster in Buffalo, New York.Results announced ahead of Supercomputing 2025.Collaboration between Core42, Broadcom and Arista Networks delivers a top performing and reliable HPC network with fast data transfers and minimal latency. Core42, a G42 company specializing in sovereign cloud and AI infrastructure, announced that itsMaximus-384 supercomputer has been ranked No. 20 globally on the TOP500 List, the industry’s most recognized benchmark for publicly known supercomputing systems. The ranking highlights the performance of the AMD Instinct™ MI300X GPU-based “Maximus” cluster, operated at the company’s facility in Buffalo, New York and released ahead of Supercomputing 2025, the leading global conference for HPC. The TOP500 list tracks performance trends across the global supercomputing systems using the High Performance Linpack benchmark (HPL) benchmark. Securing a top-20 position reflects exceptional enginee
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
