Cloudflare has dealt with what is now officially the largest DDoS attack ever recorded, a staggering 29.7 terabits per second. The attack came from AISURU, a botnet-for-hire that has been hammering telecom providers, gaming platforms, hosting companies, and financial services for more than a year. This latest strike lasted just 69 seconds, but its size alone makes it a milestone in the history of DDoS activity.
While Cloudflare didn’t name the target, the company confirmed that AISURU remains one of the most aggressive and well-resourced botnets active today, operating across 1–4 million infected machines worldwide.
A 29.7 Tbps “carpet-bombing” attack
Cloudflare described the incident as a massive UDP carpet-bombing attack, hitting around 15,000 destination ports every second. Packet attributes were randomized to make the traffic harder to identify and filter, a classic move from advanced botnets trying to slip past automated defenses.
This wasn’t the only record attempt from AISURU. Cloudflare also intercepted a 14.1 billion packets-per-second (Bpps) attack from the same botnet.
Since January, Cloudflare has mitigated 2,867 AISURU-linked attacks, with more than 1,300 “hyper-volumetric” attacks occurring in Q3 alone. Across all botnets, Cloudflare blocked 8.3 million DDoS attacks in Q3 2025, up 40% from last year.
DDoS trends from Q3 2025
Cloudflare’s telemetry shows how quickly the threat landscape is scaling:
Attack Volumes & Growth
1. 36.2 million DDoS attacks blocked in 2025 so far
2. 1,304 network-layer attacks exceeded 1 Tbps
3. Attacks over 100 Mpps jumped 189% quarter-over-quarter
4. Most attacks between 71% and 89% lasted under 10 minutes, suggesting “hit-and-run” tactics
Top Global Sources
Seven of the top ten botnet origins were in Asia:
1. Indonesia
2. Thailand
3. Bangladesh
4. Vietnam
5. India
6. Hong Kong
7. Singapore
Other significant sources:
Ecuador, Russia, and Ukraine
Most Targeted Sectors
1. Information Technology
2. Telecommunications
3. Internet services
4. Gaming and gambling
5. Financial services
6. Automotive saw the largest YoY increase
7. Mining & mineral industries also saw a sharp rise
Attacks targeting AI companies surged 347% in September alone, a sign that attackers are already trying to exploit the AI boom.
Botnets are doing most of the heavy lifting
Nearly 70% of HTTP DDoS attacks originated from known botnet infrastructure, signaling that automation and widespread infection are driving the surge.
What this means for organizations
Cloudflare summed it up bluntly:
“We’ve entered an era where DDoS attacks have rapidly grown in sophistication and size beyond anything we could’ve imagined a few years ago.”
For many organizations, this shift means that:
1. Traditional firewalls are no longer enough
2. On-prem appliances can't absorb multi-Tbps floods
3. Attackers are using larger, more globally distributed botnets
4. Even short attacks can cause costly outages
Defenses now need to be always-on, cloud-based, and capable of automated response, because humans can’t manually react to attacks measured in terabits.
Source: The Hacker News