Asia-Pacific
Flag of China

China

The DDoS threat landscape is constantly evolving, and to stay ahead of adversaries, ongoing monitoring and analysis are essential to detect how they are modifying their behavior and targets. NETSCOUT monitors the global threat landscape and drills into regional and country-level statistics to ensure that adversaries inform us of near-real-time trends. The country-level analytics featured on this page are automatically generated using our global threat analysis and collection platform, ATLAS, and provide a range of benchmarks for the specified time period, such as the top vectors used in DDoS attacks, top targeted industries, most vectors used in an attack, and total attack frequency.

Max Multivector Attack

Max number of vectors seen in a single attack

18

Attack Vectors Used

1. CLDAP Amplification
2. DNS Amplification
3. ICMP
4. L2TP Amplification
5. MS SQL RS Amplification
6. NTP Amplification
7. NetBIOS Amplification
8. RIPv1 Amplification
9. SLP Amplification
10. SNMP Amplification
11. SSDP Amplification
12. UDP
13. chargen Amplification
14. mDNS Amplification
15. memcached Amplification
16. rpcbind Amplification

Top Attack Vectors

Ts

TCP SYN

Number of Attacks

67,458

Dn

DNS Amplification

Number of Attacks

13,815

Ta

TCP ACK

Number of Attacks

7,643

Ds

DNS

Number of Attacks

4,179

Cd

CLDAP Amplification

Number of Attacks

3,593

Top Six Industries Under Attack

The following table lists the top vertical industries under attack from January 2026 to June 2026 by number of attacks.

Rank Vertical Frequency Average Duration
1
Wired Telecommunications Carriers
40,576 26 Minutes
2
Computing Infrastructure Providers Data Processing Web Hosting and Related Services
22,629 25 Minutes
3
Wireless Telecommunications Carriers (except Satellite)
22,083 43 Minutes
4
Book Retailers and News Dealers
2,472 29 Minutes
5
Telecommunications Resellers
847 23 Minutes
6
Television Broadcasting Stations
505 29 Minutes