Adversaries Continue Cyberattack Onslaught with Greater Precision and Innovative Attack Methods according to 1H2022 NETSCOUT DDoS Threat Intelligence Report
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) today announced findings from its 1H2022 DDoS Threat Intelligence Report. The findings demonstrate how sophisticated cybercriminals have become at bypassing defenses with new DDoS attack vectors and successful methodologies.
"By constantly innovating and adapting, attackers are designing new, more effective DDoS attack vectors or doubling down on existing effective methodologies," said Richard Hummel, threat intelligence lead, NETSCOUT. "In the first half of 2022, attackers conducted more pre-attack reconnaissance, exercised a new attack vector called TP240 PhoneHome, created a tsunami of TCP flooding attacks, and rapidly expanded high-powered botnets to plague network-connected resources. In addition, bad actors have openly embraced online aggression with high-profile DDoS attack campaigns related to geopolitical unrest, which have had global implications."
Deployed in most of the world's ISPs, large data centers, and government and enterprise networks, NETSCOUT Arbor DDoS attack protection solutions send anonymized DDoS attack statistics to NETSCOUT's Active Level Threat Analysis System (ATLAS™). This data, which includes visibility into more than 190 countries, 550 industries, and 50,000 autonomous system numbers (ASNs), is then analyzed and curated by NETSCOUT's ATLAS Security Engineering and Response Team (ASERT) to provide unique insights in the report. No other vendor sees and knows more about DDoS attack activity and best practices in protection than NETSCOUT.
Key findings from the 1H2022 NETSCOUT DDoS Threat Intelligence Report include:
- There were 6,019,888 global DDoS attacks in 1st half of 2022.
- TCP-based flood attacks (SYN, ACK, RST) remain the most used attack vector, with approximately 46% of all attacks continuing a trend that started in early 2021.
- DNS water-torture attacks accelerated into 2022 with a 46% increase primarily using UDP query floods, while carpet-bombing attacks experienced a big comeback toward the end of the second quarter; overall, DNS amplification attacks decreased by 31% from 2H2021 to 1H2022.
- The new TP240 PhoneHome reflection/amplifications DDoS vector was discovered in early 2022 with a record-breaking amplification ratio of 4,293,967,296:1; swift actions eradicated the abusable nature of this service.
- Malware botnet proliferation grew at an alarming rate, with 21,226 nodes tracked in the first quarter to 488,381 nodes in the second, resulting in more direct-path, application-layer attacks.
Geopolitical Unrest Spawns Increased DDoS Attacks
As Russian ground troops entered Ukraine in late February, there was a significant uptick in DDoS attacks targeting governmental departments, online media organizations, financial firms, hosting providers, and cryptocurrency-related firms, as previously documented. However, the ripple effect resulting from the war had a dramatic impact on DDoS attacks in other countries too, including:
- Ireland experienced a surge in attacks after providing service to Ukrainian organizations.
- India experienced a measurable increase in DDoS attacks following its abstention from the UN Security Council and General Assembly votes condemning Russia's actions in Ukraine.
- On the same day, Taiwan endured its single-highest number of DDoS attacks after making public statements supporting Ukraine, as with Belize.
- Finland experienced a 258% increase in DDoS attacks year-over-year, coinciding with its announcement to apply for NATO membership.
- Poland, Romania, Lithuania, and Norway were targeted by DDoS attacks linked to Killnet; a group of online attackers aligned with Russia.
- While the frequency and severity of DDoS attacks in North America remained relatively consistent, satellite telecommunications providers experienced an increase in high-impact DDoS attacks, especially after providing support for Ukraine's communications infrastructure.
- Russia experienced a nearly 3X increase in daily DDoS attacks since the conflict with Ukraine began and continued through the end of the reporting period.
Similarly, as tensions between Taiwan, China, and Hong Kong escalated in 1H2022, DDoS attacks against Taiwan regularly occurred in concert with related public events.
NETSCOUT's DDoS Threat Intelligence Report covers the latest trends and activities in the DDoS threat landscape. It covers data captured from NETSCOUT's ATLAS and expert insights from ASERT.
The visibility and insights compiled from the global DDOS attack data, represented in the DDoS Threat Intelligence Report, and seen in the Omnis Threat Horizon portal, fuel the ATLAS Intelligence Feed (AIF). In addition, AIF continuously arms NETSCOUT's Omnis and Arbor security portfolio enabling them to automatically detect and block threat activity for enterprises and service providers worldwide.
Visit our interactive website for more information on NETSCOUT's semi-annual DDoS Threat Intelligence Report. You can also find us on Facebook, LinkedIn , and Twitter for threat updates and the latest trends and insights.
About NETSCOUT
NETSCOUT SYSTEMS, INC. (NASDAQ: NTCT) protects the connected world from cyberattacks and performance disruptions through advanced network detection and response and pervasive network visibility. Powered by our pioneering deep packet inspection at scale, we serve the world's largest enterprises, service providers, and public sector organizations. Learn more at www.netscout.com or follow @NETSCOUT on LinkedIn, Twitter, or Facebook.
©2022 NETSCOUT SYSTEMS, INC. All rights reserved. NETSCOUT, the NETSCOUT logo, Guardians of the Connected World, Adaptive Service Intelligence, Arbor, ATLAS, Cyber Threat Horizon, InfiniStream, nGenius, nGeniusONE, and Omnis are registered trademarks or trademarks of NETSCOUT SYSTEMS, INC., and/or its subsidiaries and/or affiliates in the USA and/or other countries. Third-party trademarks mentioned are the property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220927005076/en/
Contact information
Editorial Contacts:
Maribel Lopez
Manager, Marketing & Corporate Communications
+1 781 362 4330
maribel.lopez@netscout.com
Chris Shattuck
Finn Partners for NETSCOUT
+1 678 504 6785
NETSCOUT-US@FinnPartners.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Synthio Labs Raises $5 Million to Build the Voice AI Operating System for Life Sciences Customer Engagement19.11.2025 17:00:00 EET | Press release
Synthio Labs, a clinical-grade voice AI company transforming how life sciences organisations engage clinicians and patients, today announced that it has raised $5 million in seed funding. The round was led by Elevation Capital with participation from 1984 Ventures, Peak XV Partners, Y Combinator, and several strategic angels from the global healthcare and AI ecosystem. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251119509940/en/ Rajashekar Vasantha (left), Supreet Deshpande (center), and Sahitya Sridhar (right), the founding team behind Synthio Labs’ voice-powered AI platform for pharma “We believe Synthio Labs is defining the next major Customer Engagement infrastructure for Life Sciences. Their Clinical-grade Voice AI platform unifies how pharma communicates - giving field teams a powerful voice companion, and giving physicians and patients instant, trusted, compliant answers 24/7. Pharma’s global Commercial and GTM foo
Torq Crushes EMEA Estimates With Record-Breaking Q3, Hitting 185% of Quarterly Target19.11.2025 16:00:00 EET | Press release
Torq, the autonomous security operations leader, today announced it has exceeded Q3 EMEA revenue estimates, achieving 185% of its quarterly target. Torq is now firmly established as EMEA’s autonomous security operations platform of choice as enterprise goliaths continue joining its customer ranks, including Virgin Atlantic, Kyocera, Siemens, and Zara. Torq’s EMEA headcount grew 400% across 2025 to accommodate the exponentially increasing demand. “As worldwide momentum accelerates, Torq is doubling down on its EMEA investment by expanding operations, growing regional leadership, and strengthening our on-the-ground presence to fuel our next stage of growth,” said Ofer Smadari, CEO and co-founder, Torq. “Torq is now trusted by many of the world’s largest brands inside some of the most complex and sophisticated security operations centers. With new expansion into Germany, Hungary, Poland, Slovenia, and Switzerland, we are continuing to scale our footprint across the region. EMEA’s most suc
Xsolla Releases “The Xsolla Report: State of Play Q3 2025 Edition, Vol. 8,” Delivering Clear, Data-Led Insights for Game Developers19.11.2025 16:00:00 EET | Press release
Xsolla, a global video game commerce company that helps developers launch, grow, and monetize their products, today announces the release of The Xsolla Report: State of Play Q3 2025 Edition, Vol. 8, a comprehensive analysis of market forces shaping the games industry. The report synthesizes the latest data and expert perspectives to help developers and publishers plan for sustainable growth across platforms and regions. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251119397781/en/ Graphic: Xsolla As developers navigate new distribution models and evolving monetization approaches, the Q3 2025 edition offers a practical perspective on where the market is heading. The global player base is projected to reach 3.6 billion by year-end, with revenue on track to reach $188.8 billion—driven by steady momentum, including console hardware refreshes, PC gains in Asia, and ongoing strength in mobile. Key highlights from the Q3 2025 edi
iConnections Launches Pipelines: A Powerful New Way for LPs and GPs to Turn Connections Into Real Momentum19.11.2025 16:00:00 EET | Press release
iConnections, the leading network for allocators and fund managers, today announced the launch of Pipelines, a new productivity and relationship-management tool built directly into the platform. Pipelines gives LPs and GPs a structured, visual, and purpose-built way to organize their outreach, nurture relationships, and drive their fundraising or investment processes forward—without relying on fragmented spreadsheets or generic CRMs. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251119021208/en/ Born from extensive feedback across the alternative investment ecosystem, Pipelines is designed to solve a common industry challenge: after a productive event or outreach cycle, promising conversations often lose momentum because there is no simple, tailored way to track next steps. “With Pipelines, users finally have a workflow that matches the way this industry actually operates,” said Douglas Melchior, VP of Product at iConnectio
PicSee Launches the World’s First Social Platform That Helps You Get All Your Photos from Friends19.11.2025 16:00:00 EET | Press release
PicSee, a new kind of social platform, announced its global launch - introducing a revolutionary way for friends and family to reconnect through photos. Built on mutual photo sharing and powered by AI, PicSee helps users automatically get all their photos from friends by giving them theirs - without ever uploading them to the cloud. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251112904808/en/ PicSee App - Home Screen Every year, trillions of photos are captured but rarely shared with the friends in them. PicSee changes that. Using on-device facial recognition and a patent-pending “give to get” system, the app automatically identifies which photos belong to whom and helps friends exchange them securely with a single tap. PicSee scans a user’s gallery, recognizes faces, and generates a personalized invite such as: “I have 75 of your pics. Come get them on PicSee.” Once two friends approve each other, PicSee automatically ex
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
