Tuesday, December 16, 2025

FIRST WITH SECURITY NEWS

DDoS attacks continue to dominate the digital battlefield, destabilising critical infrastructure

Published on

Distributed Denial-of-Service (DDoS) attacks have evolved into precision-guided weapons of geopolitical influence capable of destabilising critical infrastructure, Netscout Systems has said in a new report that tracked over 8 million DDoS attacks in the first half of 2025.

Of the 8 million attacks, 3.2 million were monitored in Europe, the Middle East and Africa (EMEA). Hacktivist groups like NoName057(16) orchestrated hundreds of coordinated strikes each month, targeting the communications, transportation, energy, and defence sectors. DDoS-for-hire services have democratised attack tools, enabling novice actors to execute sophisticated attack campaigns. AI-enhanced automation, multi-vector attacks, and carpet bombing techniques challenge traditional defences. Botnets compromised tens of thousands of IoT devices, servers, and routers, delivering sustained attacks and causing significant disruption.

While each of these elements is dangerous on its own, in aggregate, they have formed the perfect storm, creating unprecedented cyber risk for organisations and service provider networks around the world, Netscout said.

The company observed more than 50 attacks greater than a terabit-per-second (Tbps) and multiple gigapacket-per-second (Gpps) attacks in the first half of 2025, including a 3.12 Tbps attack in the Netherlands and a 1.5 Gpps attack in the United States.

The India-Pakistan conflict saw hacktivist groups target the Indian government and financial sectors in May, while the Iran-Israel conflict generated more than 15,000 attacks against Iran and 279 against Israel in June.

More than 880 bot-driven DDoS attacks occurred daily in March, peaking at 1,600 incidents, with attack durations increasing to an average of 18 minutes.

Leveraging DDoS-for-hire infrastructure, DieNet orchestrated over 60 attacks since March, while Keymous+ launched 73 attacks across 28 industry sectors in 23 countries.

NoName057(16) maintained dominance, claiming more than 475 attacks in March alone, 337% more than the next most active group. The hacktivist group targeted government websites in Spain, Taiwan, and Ukraine.

“As hacktivist groups leverage more automation, shared infrastructure, and evolving tactics, organizations must recognize that traditional defences are no longer sufficient,” stated Richard Hummel, director, threat intelligence, Netscout. “The integration of AI assistants and the use of large language models (LLMs), such as WormGPT and FraudGPT, escalates that concern. And, while the recent takedown of NoName057(16) was successful in temporarily reducing the group’s DDoS botnet activities, preventing a future return to the top DDoS hacktivist threat is not guaranteed. Organisations need intelligence-driven, proven DDoS defences that can deal with the sophisticated attacks we see today.”

MOST READ

SITE SPONSORS

More like this

Over 100 000 cyber-attacks while SAPS records just 544 cases

Over 100 000 banking breaches in 2024 caused R1.8 billion in losses, yet the...

NETSCOUT warns of new hacktivist threat posing global risks, from the US, Middle East, Africa and beyond

DieNet, a newly emerged hacktivist group, has claimed responsibility for more than 60 distributed...

A targeted attack mimics communication from company CEO to steal funds

Over the last few weeks, Kaspersky detected a series of sophisticated attack attempts aimed...