DDoS-Capable Botnets
From January through June 2026, NETSCOUT identified 819,435 distinct DDoS-capable botnet nodes.
These distributed systems can support both direct-path and reflection/amplification attacks against enterprises and service providers worldwide.
The DDoS threat landscape continues to include diverse and evolving operational models. Persistent threat groups, including NoName057(16), remained active during the reporting period, while botnet operators continued to draw on compromised devices, proxy infrastructure, cloud-hosted resources, and amplification techniques to increase the scale and impact of attacks. These varied approaches require defenders to maintain layered protections across network and application layers, supported by timely threat intelligence and resilient mitigation capabilities.
Enterprise
Enterprise Top 5
Source Countries
-
China
-
Brazil
-
Russia
-
India
-
United States
Targeted Countries
-
Brazil
-
Vietnam
-
Indonesia
-
South Korea
-
United States
Targeted Industries
-
Wireless Telecommunications Carriers (except Satellite)
-
Wired Telecommunications Carriers
-
Software Publishers
-
Commercial Banking
-
All Other Telecommunications
Service Provider
Service Provider Top 5
Source Countries
-
Brazil
-
Russia
-
Indonesia
-
United States
-
India
Targeted Countries
-
United States
-
South Korea
-
France
-
Uzbekistan
-
Chile
Targeted Industries
-
Computing Infrastructure Providers Data Processing Web Hosting and Related Services
-
Wired Telecommunications Carriers
-
Wireless Telecommunications Carriers (except Satellite)
-
Industrial Machinery and Equipment Merchant Wholesalers
-
Marketing Consulting Services