South Africa
The DDoS threat landscape is constantly evolving, and to stay ahead of adversaries, ongoing monitoring and analysis are essential to detect how they are modifying their behavior and targets. NETSCOUT monitors the global threat landscape and drills into regional and country-level statistics to ensure that adversaries inform us of near-real-time trends. The country-level analytics featured on this page are automatically generated using our global threat analysis and collection platform, ATLAS, and provide a range of benchmarks for the specified time period, such as the top vectors used in DDoS attacks, top targeted industries, most vectors used in an attack, and total attack frequency.
Max Multivector Attack
Max number of vectors seen in a single attack
25
Attack Vectors Used
1. CLDAP Amplification
2. DNS
3. DNS Amplification
4. ICMP
5. MS SQL RS Amplification
6. NTP Amplification
7. NetBIOS Amplification
8. OpenVPN Amplification
9. RDP Amplification
10. RIPv1 Amplification
11. SNMP Amplification
12. SSDP Amplification
13. TCP ACK
14. TCP RST
15. TCP SYN
16. TCP SYN/ACK Amplification
17. UDP
18. VSE Amplification
19. chargen Amplification
20. mDNS Amplification
21. memcached Amplification
22. rpcbind Amplification
Top Attack Vectors
Ta
TCP ACK
Number of Attacks
104,352
Dn
DNS Amplification
Number of Attacks
65,097
Ds
DNS
Number of Attacks
31,529
Ts
TCP SYN
Number of Attacks
14,106
Lt
L2TP Amplification
Number of Attacks
10,723
Top Nine Industries Under Attack
The following table lists the top vertical industries under attack from January 2026 to June 2026 by number of attacks.
| Rank | Vertical | Frequency | Average Duration |
|---|---|---|---|
| 1 |
|
235,746 | 51 Minutes |
| 2 |
|
23,433 | 26 Minutes |
| 3 |
|
9,201 | 30 Minutes |
| 4 |
|
6,303 | 349 Minutes |
| 5 |
|
6,049 | 199 Minutes |
| 6 |
|
4,108 | 37 Minutes |
| 7 |
|
1,869 | 108 Minutes |
| 8 |
|
1,464 | 562 Minutes |
| 9 |
|
1,166 | 33 Minutes |