Cloudflare Q3 2025 Report Flags Surge in Hyper-Volumetric DDoS Attacks Driven by Aisuru
Cloudflare’s Q3 2025 DDoS Threat Report paints a stark picture of the evolving cyber threat landscape, marked by record-breaking attack volumes, increasingly sophisticated botnets, and rising geopolitical tensions that are reshaping digital risk worldwide. Powered by telemetry from one of the largest networks on the internet, the report reveals how attackers are shifting their focus to high-profile industries while deploying unprecedented levels of disruptive force.
Aisuru: The Botnet Redefining Hyper-Volumetric Attacks
At the heart of this escalation is Aisuru, a sprawling botnet comprising an estimated 1–4 million compromised hosts. It regularly launches attacks exceeding:
- 1 Tbps bandwidth, and
- 1 billion packets per second (pps)
Cloudflare reports a 54% quarter-on-quarter surge in hyper-volumetric attacks, signaling a new era of botnets engineered for extreme throughput and overwhelming network capacity.
Meanwhile, AI companies have emerged as a prime target, experiencing a staggering 347% month-on-month spike in DDoS traffic — a trend Cloudflare links to public scrutiny, regulatory pressure, and the soaring economic value of AI-driven services.
“DDoS activity is now tightly linked to geopolitical tensions and high-growth digital sectors.”
— Bashar Bashaireh, Area VP, Middle East, Türkiye & North Africa, Cloudflare
Geopolitics Drives Target Selection
Global tensions — particularly EU–China disputes over rare earth minerals and EV tariffs — shaped attackers’ priorities. Industries caught in the geopolitical crossfire saw pronounced increases in DDoS activity:
- Mining, Minerals & Metals climbed sharply in attack frequency
- Automotive jumped 62 ranks to become the sixth most targeted sector globally
Critical infrastructure continues to face sustained pressure as DDoS becomes a tool for economic signaling and political retaliation.
2025 on Track to Become the Most Active DDoS Year in History
Cloudflare mitigated:
- 8.3 million attacks in Q3 alone — a 40% YoY increase
- 36.2 million attacks in 2025 year-to-date — already 170% higher than all of 2024
Network-layer attacks dominated the threat landscape, representing 71% of all activity and growing nearly 90% quarter-on-quarter. Key drivers include:
- UDP floods
- DNS-based abuse
- Mirai-derived botnet strains that continue to evolve and propagate
Asia Leads Global Attack Origination
Asia remained the largest source of malicious traffic, with:
- Indonesia as the top origin of attacks
- China, Turkey, and Germany among the most targeted nations
- The United States climbing 11 positions, suggesting rising attacker focus on Western digital ecosystems


