Cloudflare Reports Significant Drop in DDoS Attacks for Q2 2025
Date: July 15, 2025
Author: Ravie Lakshmanan
Tags: Botnet, Network Security
Overview of DDoS Attack Trends
In a recent update, Cloudflare announced that it successfully mitigated 7.3 million distributed denial-of-service (DDoS) attacks in the second quarter of 2025. This figure signifies a notable decrease from the 20.5 million DDoS attacks it thwarted during the first quarter. Despite this reduction, Cloudflare reported an increase in hyper-volumetric attacks, which are characterized by particularly large data transmissions that can overwhelm networks more efficiently than typical attacks.
Rise of Hyper-Volumetric DDoS Attacks
Omer Yoachimik and Jorge Pacheco from Cloudflare noted that the second quarter experienced a surge in hyper-volumetric DDoS attacks, with the company blocking an average of 71 per day. In total, over 6,500 such attacks were mitigated. In stark contrast to this rise, Q1 2025 saw significant challenges, including an 18-day sustained assault targeting vital infrastructure, accounting for a large portion of that quarter’s DDoS activities.
Overall, Cloudflare has thwarted nearly 28 million DDoS attacks to date, surpassing the total attacks mitigated throughout all of 2024.
Details of Major Attacks
One particularly massive DDoS assault reached an impressive peak of 7.3 terabits per second (Tbps) and generated 4.8 billion packets per second (Bpps) within a mere 45 seconds. Such extreme traffic fluctuations are newsworthy but can obscure the more sophisticated strategies employed by attackers. Instead of relying solely on overwhelming systems with sheer volume, they often integrate smaller targeted scans to identify vulnerabilities in systems.
Analysis of Attack Types
While Cloudflare observed an 81% decrease in Layer 3 and Layer 4 (L3/4) DDoS attacks—totaling about 3.2 million—HTTP DDoS attacks actually rose by 9% to 4.1 million. Notably, over 70% of these HTTP attacks originated from recognized botnets. The predominant L3/4 attack vectors consisted of flood assaults utilizing DNS, TCP SYN, and UDP protocols.
Telecommunication service providers were among the primary targets, alongside sectors such as internet services, IT, gaming, and gambling.
Geographic Distribution of Attacks
Regions with the highest incidence of attacks included China, Brazil, Germany, India, South Korea, and several others. On the flip side, countries such as Indonesia, Singapore, and Ukraine contributed significantly as sources of DDoS attacks.
Cloudflare also flagged a remarkable 592% increase in hyper-volumetric DDoS attacks surpassing 100 million packets per second (pps) compared to the previous quarter. This escalation highlights the evolving nature and intensity of cyber threats.
Ransom DDoS Attacks on the Rise
Another alarming trend is the 68% increase in ransom DDoS attacks. In these scenarios, attackers threaten organizations with DDoS assaults unless a ransom is paid. These attacks can force compliance from organizations by putting their operations at risk if their demands are not met.
Cloudflare’s findings indicate that hyper-volumetric DDoS attacks are growing not only in size but also in frequency. Remarkably, 6 out of 100 HTTP DDoS attacks exceeded 1 million requests per second (rps), and 5 out of every 10,000 L3/4 DDoS attacks surpassed 1 Tbps, reflecting an astonishing 1,150% quarter-over-quarter increase.
The Threat of DemonBot
The company also highlighted the emergence of a concerning botnet variant known as DemonBot, which primarily targets Linux-based systems. This botnet exploits unsecured IoT devices through open ports or weak credentials, integrating them into a DDoS network capable of delivering UDP, TCP, and application-layer floods.
Cloudflare emphasized that these attacks are generally command-and-control driven and can generate substantial volumetric traffic, typically targeting gaming platforms, enterprise services, and hosting providers. To mitigate potential risks from such botnets, users are encouraged to utilize strong antivirus software and implement domain filtering.
Challenges in Network Security
DemonBot exemplifies broader issues surrounding unsecured IoT devices, often exacerbated by weak SSH credentials and outdated firmware. These vulnerabilities are common across many DDoS botnets. Attack methodologies such as TCP reflection, DNS amplification, and burst-layer evasion are becoming more prevalent and are often discussed in Cloudflare’s ongoing threat reports regarding application-layer security.
For organizations, it remains critical to stay vigilant against these threats by reinforcing their cyber defenses. The evolving landscape of DDoS attacks necessitates a proactive approach to safeguarding network integrity.


