Adversaries Continue Cyberattack Onslaught with Greater Precision and Innovative Attack Methods according to 1H2022 NETSCOUT DDoS Threat Intelligence Report
27.9.2022 13:05:00 EEST | Business Wire | Press release
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) today announced findings from its 1H2022 DDoS Threat Intelligence Report. The findings demonstrate how sophisticated cybercriminals have become at bypassing defenses with new DDoS attack vectors and successful methodologies.
"By constantly innovating and adapting, attackers are designing new, more effective DDoS attack vectors or doubling down on existing effective methodologies," said Richard Hummel, threat intelligence lead, NETSCOUT. "In the first half of 2022, attackers conducted more pre-attack reconnaissance, exercised a new attack vector called TP240 PhoneHome, created a tsunami of TCP flooding attacks, and rapidly expanded high-powered botnets to plague network-connected resources. In addition, bad actors have openly embraced online aggression with high-profile DDoS attack campaigns related to geopolitical unrest, which have had global implications."
Deployed in most of the world's ISPs, large data centers, and government and enterprise networks, NETSCOUT Arbor DDoS attack protection solutions send anonymized DDoS attack statistics to NETSCOUT's Active Level Threat Analysis System (ATLAS™). This data, which includes visibility into more than 190 countries, 550 industries, and 50,000 autonomous system numbers (ASNs), is then analyzed and curated by NETSCOUT's ATLAS Security Engineering and Response Team (ASERT) to provide unique insights in the report. No other vendor sees and knows more about DDoS attack activity and best practices in protection than NETSCOUT.
Key findings from the 1H2022 NETSCOUT DDoS Threat Intelligence Report include:
- There were 6,019,888 global DDoS attacks in 1st half of 2022.
- TCP-based flood attacks (SYN, ACK, RST) remain the most used attack vector, with approximately 46% of all attacks continuing a trend that started in early 2021.
- DNS water-torture attacks accelerated into 2022 with a 46% increase primarily using UDP query floods, while carpet-bombing attacks experienced a big comeback toward the end of the second quarter; overall, DNS amplification attacks decreased by 31% from 2H2021 to 1H2022.
- The new TP240 PhoneHome reflection/amplifications DDoS vector was discovered in early 2022 with a record-breaking amplification ratio of 4,293,967,296:1; swift actions eradicated the abusable nature of this service.
- Malware botnet proliferation grew at an alarming rate, with 21,226 nodes tracked in the first quarter to 488,381 nodes in the second, resulting in more direct-path, application-layer attacks.
Geopolitical Unrest Spawns Increased DDoS Attacks
As Russian ground troops entered Ukraine in late February, there was a significant uptick in DDoS attacks targeting governmental departments, online media organizations, financial firms, hosting providers, and cryptocurrency-related firms, as previously documented. However, the ripple effect resulting from the war had a dramatic impact on DDoS attacks in other countries too, including:
- Ireland experienced a surge in attacks after providing service to Ukrainian organizations.
- India experienced a measurable increase in DDoS attacks following its abstention from the UN Security Council and General Assembly votes condemning Russia's actions in Ukraine.
- On the same day, Taiwan endured its single-highest number of DDoS attacks after making public statements supporting Ukraine, as with Belize.
- Finland experienced a 258% increase in DDoS attacks year-over-year, coinciding with its announcement to apply for NATO membership.
- Poland, Romania, Lithuania, and Norway were targeted by DDoS attacks linked to Killnet; a group of online attackers aligned with Russia.
- While the frequency and severity of DDoS attacks in North America remained relatively consistent, satellite telecommunications providers experienced an increase in high-impact DDoS attacks, especially after providing support for Ukraine's communications infrastructure.
- Russia experienced a nearly 3X increase in daily DDoS attacks since the conflict with Ukraine began and continued through the end of the reporting period.
Similarly, as tensions between Taiwan, China, and Hong Kong escalated in 1H2022, DDoS attacks against Taiwan regularly occurred in concert with related public events.
NETSCOUT's DDoS Threat Intelligence Report covers the latest trends and activities in the DDoS threat landscape. It covers data captured from NETSCOUT's ATLAS and expert insights from ASERT.
The visibility and insights compiled from the global DDOS attack data, represented in the DDoS Threat Intelligence Report, and seen in the Omnis Threat Horizon portal, fuel the ATLAS Intelligence Feed (AIF). In addition, AIF continuously arms NETSCOUT's Omnis and Arbor security portfolio enabling them to automatically detect and block threat activity for enterprises and service providers worldwide.
Visit our interactive website for more information on NETSCOUT's semi-annual DDoS Threat Intelligence Report. You can also find us on Facebook, LinkedIn , and Twitter for threat updates and the latest trends and insights.
About NETSCOUT
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) protects the connected world from cyberattacks and performance disruptions through advanced network detection and response and pervasive network visibility. Powered by our pioneering deep packet inspection at scale, we serve the world's largest enterprises, service providers, and public sector organizations. Learn more at www.netscout.com or follow @NETSCOUT on LinkedIn, Twitter, or Facebook.
©2022 NETSCOUT SYSTEMS, INC. All rights reserved. NETSCOUT, the NETSCOUT logo, Guardians of the Connected World, Adaptive Service Intelligence, Arbor, ATLAS, Cyber Threat Horizon, InfiniStream, nGenius, nGeniusONE, and Omnis are registered trademarks or trademarks of NETSCOUT SYSTEMS, INC., and/or its subsidiaries and/or affiliates in the USA and/or other countries. Third-party trademarks mentioned are the property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220927005076/en/
Contact information
Editorial Contacts:
Maribel Lopez
Manager, Marketing & Corporate Communications
+1 781 362 4330
maribel.lopez@netscout.com
Chris Shattuck
Finn Partners for NETSCOUT
+1 678 504 6785
NETSCOUT-US@FinnPartners.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Pure Lithium Receives Australian Patent for "Lithium Metal Anode and Battery"6.8.2026 23:49:00 EEST | Press release
Pure Lithium Corporation, a vertically integrated next-generation lithium metal battery technology company, today announced that the Australian patent office has granted the company a patent (AU2025271196) titled “Lithium metal anode and battery.” Australia mines roughly half of the world’s lithium, yet has no domestic battery production at all; every battery the country uses is imported. The granted patent is directed to ways in which Pure Lithium’s technology can change that. Rather than trying to catch up in lithium-ion, Australia can leapfrog the incumbent technology and establish a next-generation industry. As worldwide demand for batteries grows, every country capable of making batteries needs to be making them. That is Pure Lithium’s central goal: opening up markets around the world through battery technology that enables local, independent supply chains, keeping pace with demand and strengthening economies. China controls the lithium-ion battery supply chain and manufactures th
Vercel Appoints Amit Agarwal, Standard Template Labs CEO and former Datadog President, to Board of Directors6.8.2026 18:00:00 EEST | Press release
Vercel, the agentic infrastructure company, today announced the appointment of Amit Agarwal, former president of Datadog and founder and CEO of Standard Template Labs, an AI-first service management platform, to its board of directors. Agarwal brings 25 years of enterprise software experience and a track record of scaling a product-led company from its earliest days into one of the defining public software companies of the cloud era. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260806738617/en/ Amit Agarwal Agarwal joined Datadog in 2012 as its Chief Product Officer and was named President in 2022, overseeing product, corporate development, and go-to-market functions as the company grew past $2.5 billion in annual revenue. Across 13 years, including Datadog's 2019 IPO and its first years as a public company, Agarwal helped build one of the industry's most studied examples of product-led growth at enterprise scale. He conti
Laserfiche Launches Advanced Enterprise Security to Deliver Multi-Region Disaster Recovery and GovRAMP-Ready Compliance for Highly Regulated Industries6.8.2026 17:00:00 EEST | Press release
Laserfiche — the leading SaaS provider of intelligent content management — today announced the launch of Enterprise Security, an advanced suite of security enhancements designed for organizations navigating complex regulatory environments. Enterprise Security addresses GovRAMP and CJIS (Criminal Justice Information Services) security requirements based on the NIST SP 800-53 framework. For organizations handling privileged citizen, legal or corporate data, these built-in controls streamline audit preparation and fortify defenses. With organizations placing a higher priority on data stewardship and corporate governance, enterprise IT leaders require a security architecture that protects data without slowing down operations. Laserfiche Enterprise Security extends Laserfiche Cloud’s highly resilient infrastructure with multi-region data replication, elevated security controls for privileged accounts, and built-in governance safeguards. “Maintaining data integrity and compliance has always
Khimji Ramdas Group Chooses Rimini Street to Reduce SAP Support Costs, Protect 700+ Customizations and Reinvest Savings in Innovation6.8.2026 16:00:00 EEST | Press release
Rimini Street, Inc. (Nasdaq: RMNI), the Software Support and Agentic AI ERP Company™ and the leading third-party support provider for Oracle, SAP and VMware software, today announced that Khimji Ramdas Group, one of Oman’s largest privately held conglomerates, has selected Rimini Support™ for SAP, a move that has helped the organization reduce costs, reinvest savings in AI innovation and maintain its highly customized SAP ECC 6 environment with zero downtime. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260806244148/en/ Khimji Ramdas Group Chooses Rimini Street to Reduce SAP Support Costs, Protect 700+ Customizations and Reinvest Savings in Innovation “Staying on SAP ECC is a strategic decision for us,” said Prashant Kumar, CTO, Khimji Ramdas Group. “We went to an industry analyst to ask what options we have to keep our ECC systems running without vendor support dependencies, and they suggested that we contact Rimini Stree
AM Best Upgrades Fortegra Insurance Subsidiaries to A (Excellent)6.8.2026 16:00:00 EEST | Press release
The Fortegra Group, Inc. (“Fortegra” or the “Company”), a global specialty insurer and part of DB Insurance Co., Ltd., today announced that AM Best has upgraded the Financial Strength Rating (FSR) of its insurance subsidiaries to A (Excellent) from A- (Excellent) and the Long-Term Issuer Credit Ratings (Long-Term ICRs) to “a” (Excellent) from “a-” (Excellent). The outlook assigned to the ratings is stable, and AM Best removed the ratings from under review with positive implications. KBRA has also upgraded all of its ratings for the Company. The upgrade applies across Fortegra’s insurance platform. The property and casualty companies include Lyndon Southern Insurance Company, Insurance Company of the South, Response Indemnity Company of California, Blue Ridge Indemnity Company, Fortegra Specialty Insurance Company and Fortegra Europe Insurance Company SE. The life and health companies include Life of the South Insurance Company, Bankers Life Insurance Company of Louisiana and Southern F
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
