https://newsletter.en.creamermedia.com
Aggregate|Business|composite|Defence|Infrastructure|Innovation|Power|SECURITY|Service|Services|System|Systems|Underground|Equipment|Infrastructure|Operations
Aggregate|Business|composite|Defence|Infrastructure|Innovation|Power|SECURITY|Service|Services|System|Systems|Underground|Equipment|Infrastructure|Operations
aggregate|business|composite|defence|infrastructure|innovation|power|security|service|services|system|systems|underground|equipment|infrastructure|operations

NetScout reveals qualitative shifts in DDoS attack sophistication, infrastructure capacity, and threat actor capabilities

5th March 2026

     

Font size: - +

This article has been supplied and will be available for a limited time only on this website.

NETSCOUT® SYSTEMS, INC. (NASDAQ: NTCT), today released its second half of the year 2025 Distributed Denial-of-Service (DDoS) Threat Intelligence Report, revealing sophisticated attacker collaboration, resilient botnets, and compromised IoT infrastructure that drove more than eight million DDoS attacks worldwide – some as large as 30 terabits per second (Tbps) – marking a new era of hyper-scale, coordinated threat activity that continues to outpace global takedown efforts. Meanwhile, the accelerating growth of DDoS-for-hire services is empowering a broader range of threat actors, intensifying operational risk to digitally connected organisations and enterprises.

Implications for security professionals extend far beyond volumetric concerns and include reconnaissance and adaptive evasion which challenge traditional defence paradigms. Organisations must match adversarial innovation with intelligent, autonomous defences, or risk operational disruption at levels previously considered theoretical.

“Threat actors identify organisations that haven’t invested in the right defences to stay ahead of sophisticated and coordinated DDoS attacks to take down critical infrastructure,” stated Richard Hummel, director, threat intelligence, NETSCOUT. “Traditional security defences are no longer working, and with attackers hitting new attack size and complexity ceilings, implementing automated and proactive defences has become a business-level risk mandate – not just a technical concern for security professionals.”

Key research findings include:

·       Massive attacks on a global scale – More than eight million attacks were identified across 203 countries and territories globally.

·       Continued use of multi-vector attacks – approximately 42% of DDoS attacks employed two to five distinct attack vectors, with some adapting dynamically throughout the attack to complicate detection and mitigation.

·       Outbound attacks impact broadband and mobile services – Extensive direct-path attacks revealed that compromised IoT and customer-premises equipment can generate outbound floods exceeding 1 Tbps, creating liability, service, and reputational risk for broadband and mobile providers.

·       Critical infrastructure targeted – High‑value services such as NTP and DNS continue to face sustained attack pressure, emphasising the need for resilient, globally distributed architectures to maintain service continuity.

·       Threat actors scale up collaboration – A surge of more than 20,000 botnet-driven attacks in July 2025 exemplified how coordinated threat activity can rapidly overwhelm defences and disrupt critical government, finance, and transportation services.

·       Threat actor persistence – Despite international law enforcement dismantling multiple DDoS-for-hire platforms, hacktivist groups and botnets remain resilient, exerting increased pressure.

·       AI integration accelerates operations and collaboration – AI has transitioned to an operational reality, with large language models (LLMs) on the dark web accelerating vulnerability exploitation and botnet expansion, and underground forums documenting a 219% increase in mentions of malicious AI tools. Groups like Keymous+ have demonstrated how partnerships between threat actors amplify attack power, with bandwidth increasing nearly fourfold.

NETSCOUT maps the DDoS landscape through passive, internet vantage points, providing unparalleled visibility into global attack trends. For more than 15 years, NETSCOUT has delivered trusted, consistent DDoS Intelligence based exclusively on directly observed, verifiable attack traffic. NETSCOUT does not aggregate multiple alerts or geographically distributed events into composite peak values, ensuring accuracy, repeatability, and true comparability across reporting periods. Peak metrics reflect single-second maximum bits-per-second (bps) and packets-per-second (pps) rates measured at defined mitigation and monitoring points.

NETSCOUT protects two-thirds of the routed IPv4 space, securing network edges that carried global peak traffic of over 800 Tbps, covering 376 industry verticals and 12,698 Autonomous System Numbers (ASNs) in the second half of 2025. It monitors tens of thousands of daily DDoS attacks by tracking multiple botnets and DDoS-for-hire services that leverage millions of abused or compromised devices.

Edited by Creamer Media Reporter

Article Enquiry

Email Article

Save Article

Feedback

To advertise email advertising@creamermedia.co.za or click here

Latest News

Showroom

Bell Equipment
Bell Equipment

As one of South Africa's leading manufacturers, Bell Equipment distributes and exports its wide range of heavy equipment globally to mining,...

VISIT SHOWROOM 
AQS Liquid Transfer
AQS Liquid Transfer

AxFlow AQS Liquid Transfer (Pty) Ltd is an Importer and Distributor of Pumps in Southern Africa

VISIT SHOWROOM 

Latest Multimedia

sponsored by

Magazine round up | 27 February 2026
Magazine round up | 27 February 2026
27th February 2026

Option 1 (equivalent of R125 a month):

Receive a weekly copy of Creamer Media's Engineering News & Mining Weekly magazine
(print copy for those in South Africa and e-magazine for those outside of South Africa)
Receive daily email newsletters
Access to full search results
Access archive of magazine back copies
Access to Projects in Progress
Access to ONE Research Report of your choice in PDF format

Option 2 (equivalent of R375 a month):

All benefits from Option 1
PLUS
Access to Creamer Media's Research Channel Africa for ALL Research Reports, in PDF format, on various industrial and mining sectors including Electricity; Water; Energy Transition; Hydrogen; Roads, Rail and Ports; Coal; Gold; Platinum; Battery Metals; etc.

Already a subscriber?

Forgotten your password?

MAGAZINE & ONLINE

SUBSCRIBE

RESEARCH CHANNEL AFRICA

SUBSCRIBE

CORPORATE PACKAGES

CLICK FOR A QUOTATION







301

sq:0.027 0.123s - 139pq - 2rq
Subscribe Now