Adversaries Continue Cyberattack Onslaught with Greater Precision and Innovative Attack Methods according to 1H2022 NETSCOUT DDoS Threat Intelligence Report
27.9.2022 13:05:00 EEST | Business Wire | Press release
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) today announced findings from its 1H2022 DDoS Threat Intelligence Report. The findings demonstrate how sophisticated cybercriminals have become at bypassing defenses with new DDoS attack vectors and successful methodologies.
"By constantly innovating and adapting, attackers are designing new, more effective DDoS attack vectors or doubling down on existing effective methodologies," said Richard Hummel, threat intelligence lead, NETSCOUT. "In the first half of 2022, attackers conducted more pre-attack reconnaissance, exercised a new attack vector called TP240 PhoneHome, created a tsunami of TCP flooding attacks, and rapidly expanded high-powered botnets to plague network-connected resources. In addition, bad actors have openly embraced online aggression with high-profile DDoS attack campaigns related to geopolitical unrest, which have had global implications."
Deployed in most of the world's ISPs, large data centers, and government and enterprise networks, NETSCOUT Arbor DDoS attack protection solutions send anonymized DDoS attack statistics to NETSCOUT's Active Level Threat Analysis System (ATLAS™). This data, which includes visibility into more than 190 countries, 550 industries, and 50,000 autonomous system numbers (ASNs), is then analyzed and curated by NETSCOUT's ATLAS Security Engineering and Response Team (ASERT) to provide unique insights in the report. No other vendor sees and knows more about DDoS attack activity and best practices in protection than NETSCOUT.
Key findings from the 1H2022 NETSCOUT DDoS Threat Intelligence Report include:
- There were 6,019,888 global DDoS attacks in 1st half of 2022.
- TCP-based flood attacks (SYN, ACK, RST) remain the most used attack vector, with approximately 46% of all attacks continuing a trend that started in early 2021.
- DNS water-torture attacks accelerated into 2022 with a 46% increase primarily using UDP query floods, while carpet-bombing attacks experienced a big comeback toward the end of the second quarter; overall, DNS amplification attacks decreased by 31% from 2H2021 to 1H2022.
- The new TP240 PhoneHome reflection/amplifications DDoS vector was discovered in early 2022 with a record-breaking amplification ratio of 4,293,967,296:1; swift actions eradicated the abusable nature of this service.
- Malware botnet proliferation grew at an alarming rate, with 21,226 nodes tracked in the first quarter to 488,381 nodes in the second, resulting in more direct-path, application-layer attacks.
Geopolitical Unrest Spawns Increased DDoS Attacks
As Russian ground troops entered Ukraine in late February, there was a significant uptick in DDoS attacks targeting governmental departments, online media organizations, financial firms, hosting providers, and cryptocurrency-related firms, as previously documented. However, the ripple effect resulting from the war had a dramatic impact on DDoS attacks in other countries too, including:
- Ireland experienced a surge in attacks after providing service to Ukrainian organizations.
- India experienced a measurable increase in DDoS attacks following its abstention from the UN Security Council and General Assembly votes condemning Russia's actions in Ukraine.
- On the same day, Taiwan endured its single-highest number of DDoS attacks after making public statements supporting Ukraine, as with Belize.
- Finland experienced a 258% increase in DDoS attacks year-over-year, coinciding with its announcement to apply for NATO membership.
- Poland, Romania, Lithuania, and Norway were targeted by DDoS attacks linked to Killnet; a group of online attackers aligned with Russia.
- While the frequency and severity of DDoS attacks in North America remained relatively consistent, satellite telecommunications providers experienced an increase in high-impact DDoS attacks, especially after providing support for Ukraine's communications infrastructure.
- Russia experienced a nearly 3X increase in daily DDoS attacks since the conflict with Ukraine began and continued through the end of the reporting period.
Similarly, as tensions between Taiwan, China, and Hong Kong escalated in 1H2022, DDoS attacks against Taiwan regularly occurred in concert with related public events.
NETSCOUT's DDoS Threat Intelligence Report covers the latest trends and activities in the DDoS threat landscape. It covers data captured from NETSCOUT's ATLAS and expert insights from ASERT.
The visibility and insights compiled from the global DDOS attack data, represented in the DDoS Threat Intelligence Report, and seen in the Omnis Threat Horizon portal, fuel the ATLAS Intelligence Feed (AIF). In addition, AIF continuously arms NETSCOUT's Omnis and Arbor security portfolio enabling them to automatically detect and block threat activity for enterprises and service providers worldwide.
Visit our interactive website for more information on NETSCOUT's semi-annual DDoS Threat Intelligence Report. You can also find us on Facebook, LinkedIn , and Twitter for threat updates and the latest trends and insights.
About NETSCOUT
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) protects the connected world from cyberattacks and performance disruptions through advanced network detection and response and pervasive network visibility. Powered by our pioneering deep packet inspection at scale, we serve the world's largest enterprises, service providers, and public sector organizations. Learn more at www.netscout.com or follow @NETSCOUT on LinkedIn, Twitter, or Facebook.
©2022 NETSCOUT SYSTEMS, INC. All rights reserved. NETSCOUT, the NETSCOUT logo, Guardians of the Connected World, Adaptive Service Intelligence, Arbor, ATLAS, Cyber Threat Horizon, InfiniStream, nGenius, nGeniusONE, and Omnis are registered trademarks or trademarks of NETSCOUT SYSTEMS, INC., and/or its subsidiaries and/or affiliates in the USA and/or other countries. Third-party trademarks mentioned are the property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220927005076/en/
Contact information
Editorial Contacts:
Maribel Lopez
Manager, Marketing & Corporate Communications
+1 781 362 4330
maribel.lopez@netscout.com
Chris Shattuck
Finn Partners for NETSCOUT
+1 678 504 6785
NETSCOUT-US@FinnPartners.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Takeda’s Zasocitinib Delivered Rapid and Durable Skin Clearance in a Convenient Once-Daily Pill, Affirming Promise to Reshape Psoriasis Care28.3.2026 21:00:00 EET | Press release
Takeda(TSE:4502/NYSE:TAK)today announced new data from the two pivotal Phase 3studies of zasocitinib (TAK-279), a next-generation, highly selective oral tyrosine kinase 2 (TYK2) inhibitor, in adults with moderate-to-severe plaque psoriasis (PsO).1 Presented as a late-breaking abstract at the 2026 American Academy of Dermatology (AAD) Annual Meeting, these data show that convenient once-daily oral zasocitinib demonstrated rapid and durable skin clearance with a safety profile consistent with Phase 2b studies.1,2 “Our goal in psoriasis treatment is clear or almost clear skin, and previously this has been achieved primarily with injectable therapies,” said Melinda Gooderham, MSc, MD, FRCPC, dermatologist, SKiN Centre for Dermatology, Peterborough, Ontario, Canada, principal investigator for the Latitude PsO studies and presenting author. “These efficacy and safety results show it’s possible for a once-daily pill to deliver rapid, lasting skin clearance, highlighting the potential of zasoc
Incyte Announces New Positive 54-Week Late-Breaking Data for Povorcitinib in Hidradenitis Suppurativa at the 2026 American Academy of Dermatology (AAD) Annual Meeting28.3.2026 21:00:00 EET | Press release
Incyte (Nasdaq:INCY) today announced 54-week data evaluating the safety and efficacy of povorcitinib (INCB54707), an oral small-molecule highly-selective JAK1 inhibitor, from the pivotal Phase 3 STOP-HS clinical trial program in adult patients (≥18 years) with moderate to severe hidradenitis suppurativa (HS). The late-breaking oral presentation of these data is taking place at the 2026 American Academy of Dermatology (AAD) Annual Meeting, being held March 27-31, 2026, in Denver (Session: S034 – Late-Breaking Research: Session 2. Saturday, March 28, 2026, 1:00-4:00 p.m. MT). “The 54-week results from the STOP-HS program deliver compelling, long-term evidence supporting the potential of povorcitinib for patients with moderate to severe HS,” said Pablo J. Cagnoni, M.D., President and Global Head of Research and Development, Incyte. “Across both studies, povorcitinib demonstrated substantial and durable improvements over time in key measures of treatment success and meaningful clinical ben
AAD 2026: Late-Breaking Nemolizumab Data Demonstrate Clinically Meaningful Benefits for Children Aged 2 to 11 With Moderate-to-Severe Atopic Dermatitis28.3.2026 17:00:00 EET | Press release
Galderma (SIX: GALD) today announced new phase II data showing that nemolizumab was well tolerated and effective in children (aged 2 to 11 years) with moderate-to-severe atopic dermatitis, with a clinically meaningful and sustained reduction in skin lesions and itch for up to a year.1 Results will be presented in a late-breaking session at the 2026 American Academy of Dermatology (AAD) Annual Meeting. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260328320362/en/ Atopic dermatitis is the most common inflammatory skin disorder in children, yet treatment options in the moderate-to-severe pediatric setting are limited.5 The disease can have a significant impact on quality of life for both the patients and their loved ones, with persistent itch and recurrent skin lesions often disrupting sleep, school and relationships.5-8 “Atopic dermatitis can affect many aspects of children’s lives including schoolwork, emotional development
Angelalign Technology (6699.HK) Releases 2025 Results: Passion for Clinical Excellence Drives Worldwide Growth27.3.2026 21:56:00 EET | Press release
Angelalign Technology Inc. (6699.HK) (“Angel” or the “Company”) released its financial results for fiscal year 2025. During the reporting period, the Company continued to do well in both the global and China markets. Total case volume was 532,400, which increased 48.1%, revenue was USD 370.3 million, which increased 37.8%, and adjusted net profit was USD 43.8 million, which increased 63.0%. The results were driven by Angel’s passion for clinical excellence and its open and inclusive culture that empowers talented people to work together to meet customer needs, the Company said. Fox Hu, CEO of Angel, stated: “The clear aligner industry is complex and multidisciplinary. It requires top-tier technical and operational talent along with seamless collaboration among professionals from diverse geographies. Angel’s open and inclusive culture attracts professionals who share a passion for clinical excellence and a dedication to bringing outstanding products and services to customers. This melti
Axway Positioned as a Leader in the IDC MarketScape: Worldwide API Management 2026 Vendor Assessment27.3.2026 19:46:00 EET | Press release
Axway, a 74Software company (Euronext: 74SW) and global leader in federated API management and enterprise integration, has been named a Leader in the IDC MarketScape: Worldwide API Management 2026 Vendor Assessment.1 Axway Amplify securely connects, orchestrates, and automates data integration. Organizations in financial services, manufacturing, healthcare, and other industries rely on Amplify to modernize integrations and confidently unlock data to deliver superior digital services faster. The report notes: “The platform benefits from Axway’s long-standing experience in B2B integration, secure file transfer, and legacy connectivity, providing differentiated capabilities for organizations that need to expose and control APIs around core systems that are not cloud-native.”1 This multi-pattern expertise in security, integration, and federated governance — built during the early phases of the API-driven digital transformation — becomes especially critical as enterprises seek to govern dat
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
