DDoS-Capable Botnets

In the first half of 2024, the number of DDoS-capable botnet nodes totaled 708,756.

These nodes have been instrumental in launching both direct-path and reflection/amplification attacks against enterprises and service providers worldwide. Persistent threat groups such as NoName057(16) remain active. They continue to enhance their capabilities by employing malware families such as Mirai, exploiting open proxy servers, leveraging public cloud infrastructure, utilizing bulletproof hosting providers, and employing reflection and amplification techniques to increase the volume and impact of their attacks. These evolving tactics make it increasingly challenging for defenders to protect against these sophisticated threats.

Enterprise

666,748
Bots targeted the enterprise
25,861
Security-related events
267,172
Average packets per bot node

Service Provider

125,896
Bots targeted the enterprise
75,678
Security-related events
31
Number of vectors in top bot-sourced attack

Active DDoS Botnet Nodes