Adversaries Continue Cyberattack Onslaught with Greater Precision and Innovative Attack Methods according to 1H2022 NETSCOUT DDoS Threat Intelligence Report
27.9.2022 13:05:00 EEST | Business Wire | Press release
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) today announced findings from its 1H2022 DDoS Threat Intelligence Report. The findings demonstrate how sophisticated cybercriminals have become at bypassing defenses with new DDoS attack vectors and successful methodologies.
"By constantly innovating and adapting, attackers are designing new, more effective DDoS attack vectors or doubling down on existing effective methodologies," said Richard Hummel, threat intelligence lead, NETSCOUT. "In the first half of 2022, attackers conducted more pre-attack reconnaissance, exercised a new attack vector called TP240 PhoneHome, created a tsunami of TCP flooding attacks, and rapidly expanded high-powered botnets to plague network-connected resources. In addition, bad actors have openly embraced online aggression with high-profile DDoS attack campaigns related to geopolitical unrest, which have had global implications."
Deployed in most of the world's ISPs, large data centers, and government and enterprise networks, NETSCOUT Arbor DDoS attack protection solutions send anonymized DDoS attack statistics to NETSCOUT's Active Level Threat Analysis System (ATLAS™). This data, which includes visibility into more than 190 countries, 550 industries, and 50,000 autonomous system numbers (ASNs), is then analyzed and curated by NETSCOUT's ATLAS Security Engineering and Response Team (ASERT) to provide unique insights in the report. No other vendor sees and knows more about DDoS attack activity and best practices in protection than NETSCOUT.
Key findings from the 1H2022 NETSCOUT DDoS Threat Intelligence Report include:
- There were 6,019,888 global DDoS attacks in 1st half of 2022.
- TCP-based flood attacks (SYN, ACK, RST) remain the most used attack vector, with approximately 46% of all attacks continuing a trend that started in early 2021.
- DNS water-torture attacks accelerated into 2022 with a 46% increase primarily using UDP query floods, while carpet-bombing attacks experienced a big comeback toward the end of the second quarter; overall, DNS amplification attacks decreased by 31% from 2H2021 to 1H2022.
- The new TP240 PhoneHome reflection/amplifications DDoS vector was discovered in early 2022 with a record-breaking amplification ratio of 4,293,967,296:1; swift actions eradicated the abusable nature of this service.
- Malware botnet proliferation grew at an alarming rate, with 21,226 nodes tracked in the first quarter to 488,381 nodes in the second, resulting in more direct-path, application-layer attacks.
Geopolitical Unrest Spawns Increased DDoS Attacks
As Russian ground troops entered Ukraine in late February, there was a significant uptick in DDoS attacks targeting governmental departments, online media organizations, financial firms, hosting providers, and cryptocurrency-related firms, as previously documented. However, the ripple effect resulting from the war had a dramatic impact on DDoS attacks in other countries too, including:
- Ireland experienced a surge in attacks after providing service to Ukrainian organizations.
- India experienced a measurable increase in DDoS attacks following its abstention from the UN Security Council and General Assembly votes condemning Russia's actions in Ukraine.
- On the same day, Taiwan endured its single-highest number of DDoS attacks after making public statements supporting Ukraine, as with Belize.
- Finland experienced a 258% increase in DDoS attacks year-over-year, coinciding with its announcement to apply for NATO membership.
- Poland, Romania, Lithuania, and Norway were targeted by DDoS attacks linked to Killnet; a group of online attackers aligned with Russia.
- While the frequency and severity of DDoS attacks in North America remained relatively consistent, satellite telecommunications providers experienced an increase in high-impact DDoS attacks, especially after providing support for Ukraine's communications infrastructure.
- Russia experienced a nearly 3X increase in daily DDoS attacks since the conflict with Ukraine began and continued through the end of the reporting period.
Similarly, as tensions between Taiwan, China, and Hong Kong escalated in 1H2022, DDoS attacks against Taiwan regularly occurred in concert with related public events.
NETSCOUT's DDoS Threat Intelligence Report covers the latest trends and activities in the DDoS threat landscape. It covers data captured from NETSCOUT's ATLAS and expert insights from ASERT.
The visibility and insights compiled from the global DDOS attack data, represented in the DDoS Threat Intelligence Report, and seen in the Omnis Threat Horizon portal, fuel the ATLAS Intelligence Feed (AIF). In addition, AIF continuously arms NETSCOUT's Omnis and Arbor security portfolio enabling them to automatically detect and block threat activity for enterprises and service providers worldwide.
Visit our interactive website for more information on NETSCOUT's semi-annual DDoS Threat Intelligence Report. You can also find us on Facebook, LinkedIn , and Twitter for threat updates and the latest trends and insights.
About NETSCOUT
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) protects the connected world from cyberattacks and performance disruptions through advanced network detection and response and pervasive network visibility. Powered by our pioneering deep packet inspection at scale, we serve the world's largest enterprises, service providers, and public sector organizations. Learn more at www.netscout.com or follow @NETSCOUT on LinkedIn, Twitter, or Facebook.
©2022 NETSCOUT SYSTEMS, INC. All rights reserved. NETSCOUT, the NETSCOUT logo, Guardians of the Connected World, Adaptive Service Intelligence, Arbor, ATLAS, Cyber Threat Horizon, InfiniStream, nGenius, nGeniusONE, and Omnis are registered trademarks or trademarks of NETSCOUT SYSTEMS, INC., and/or its subsidiaries and/or affiliates in the USA and/or other countries. Third-party trademarks mentioned are the property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220927005076/en/
Contact information
Editorial Contacts:
Maribel Lopez
Manager, Marketing & Corporate Communications
+1 781 362 4330
maribel.lopez@netscout.com
Chris Shattuck
Finn Partners for NETSCOUT
+1 678 504 6785
NETSCOUT-US@FinnPartners.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Incyte’s Pivotal frontMIND Trial Showed Tafasitamab (Monjuvi ® /Minjuvi ® ) Combination Significantly Prolonged Progression-free Survival, Reducing the Risk of Disease Progression or Death by 25% in Patients with Previously Untreated, High-risk DLBCL30.5.2026 15:00:00 EEST | Press release
Incyte (Nasdaq:INCY) today announced positive results from the pivotal Phase 3 frontMIND trial evaluating the efficacy and safety of tafasitamab (Monjuvi®/Minjuvi®), a humanized Fc-modified cytolytic CD19-targeting monoclonal antibody, and lenalidomide added to R-CHOP (rituximab, cyclophosphamide, doxorubicin, vincristine and prednisone; Tafa-Len-R-CHOP) versus R-CHOP alone as a first-line treatment for adults with previously untreated diffuse large B-cell lymphoma (DLBCL) or high-grade B-cell lymphoma (HGBL). Eligible patients had an International Prognostic Index (IPI) score of 3-5, or, for patients ≤60 years of age, an age-adjusted IPI (aaIPI) of 2-3. The oral presentation of these data is taking place at the 2026 American Society of Clinical Oncology (ASCO) Annual Meeting being held May 29 – June 2, 2026, in Chicago (Abstract #LBA7000. Session: Oral Abstract Session – Hematologic Malignancies – Lymphoma and Chronic Lymphocytic Leukemia. May 30, 4:00 – 7:00 p.m. ET [3:00 – 6:00 p.m.
Fortegra Completes Acquisition by DB Insurance29.5.2026 23:30:00 EEST | Press release
The Fortegra Group, Inc. ("Fortegra"), a global specialty insurance company, today announced the completion of its acquisition by DB Insurance Co., Ltd. ("DB"), one of Korea's leading property and casualty insurers. The transaction, announced on September 26, 2025, received all required regulatory and stockholder approvals. Fortegra will operate independently, maintaining its existing leadership team, distribution relationships, and underwriting discipline. Agents, distribution partners, and customers will continue to experience the service excellence that has defined the Fortegra experience. Richard Kahlbaugh, Chairman and CEO of Fortegra, said: "Every company eventually changes ownership. That is the nature of business. The closing of this acquisition is a starting point. As part of DB Insurance, Fortegra is positioned to expand our business geographically, enhance our capabilities and deepen our market presence in the US, Europe, the United Kingdom and Asia. Together, DB Insurance a
SINOVAC Receives Nasdaq Notification Regarding Late Filing of 2025 Annual Report29.5.2026 23:01:00 EEST | Press release
Sinovac Biotech Ltd. (Nasdaq: SVA) (“SINOVAC” or the “Company”), a leading provider of biopharmaceutical products in China, today announced that it received a notification letter dated May 20, 2026 (the “Notification Letter”), from Nasdaq Listing Qualifications (“Nasdaq”) stating that as of May 8, 2026, the Company had regained compliance with the periodic filing and interim financial requirements in Nasdaq Listing Rules 5250(c)(1) (the “Periodic Filing Rule”) and 5250(c)(2), as required by the Panel’s decision dated January 21, 2026. As previously disclosed on January 22, 2026, under the Panel’s decision, SINOVAC was required to, on or before May 11, 2026, demonstrate compliance with such Nasdaq Listing Rules by completing filings of its annual report for the year ended December 31, 2024, on Form 20-F and an interim balance sheet and income statement as of the end of its second quarter of 2025 on Form 6-K. The Company timely completed such filings as required by the Panel’s decision.
From Network Automation to Agentic NetOps: NetBrain Sets the Standard for Deploying AI in Network Operations29.5.2026 16:00:00 EEST | Press release
NetBrain Technologies, Inc. today announced major new platform features that advance Agentic NetOps from an emerging category to operational reality. NetBrain's clients are already deploying agents that are diagnosing and remediating issues across complex multi-vendor enterprise networks. These new features further extend the platform with new agent tooling, cross-domain context, and open interfaces for the broader agentic enterprise. Early customer outcomes show the magnitude of the shift: A leading health insurer used NetBrain's Deep Diagnosis agent to diagnose and resolve a weeks old VPN connectivity issue in under five minutes. A large manufacturer resolved a critical device issue with a single prompt, isolating the root cause across the network path in under 20 minutes, saving hundreds of hours of engineer time, shrinking MTTR by more than 95%. A global telecommunications firm found NetBrain's context-grounded agents outperformed a stand-alone frontier LLM on a persistent firewall
Adtran resolves long-running patent litigation, reinforcing commitment to defend innovation29.5.2026 15:00:00 EEST | Press release
Adtran today announced it has resolved a patent litigation matter, resulting in a full settlement and dismissal of all claims with prejudice. The case, initiated in 2020 by a non-practicing entity asserting five patents, was transferred to the US District Court for the Northern District of Alabama in 2021 following a successful motion by Adtran. Adtran subsequently filed counterclaims, including bad-faith patent assertion under Alabama statutory law. The settlement includes payment to Adtran to resolve its counterclaims. Terms of the agreement remain confidential. “This outcome reflects a disciplined and consistent approach to protecting our innovation and our customers,” said Justin Ferguson, SVP and general counsel at Adtran. “We take all claims seriously, but we will not hesitate to defend ourselves when assertions lack merit. Situations like this place unnecessary strain on technology providers and divert resources from advancing networks and services. By advancing our counterclaim
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
