DDoS-Capable Botnets

In the first half of 2025, the number of DDoS-capable botnet nodes totaled 1,207,640.

These nodes have been instrumental in launching both direct-path and reflection/amplification attacks against enterprises and service providers worldwide. Persistent threat groups such as NoName057(16) remain active. They continue to enhance their capabilities by employing malware families such as Mirai, exploiting open proxy servers, leveraging public cloud infrastructure, utilizing bulletproof hosting providers, and employing reflection and amplification techniques to increase the volume and impact of their attacks. These evolving tactics make it increasingly challenging for defenders to protect against these sophisticated threats.

Enterprise

307,146
Security Related Events
1,091,003
Bots Targeted the Enterprise
174
Average Packets Per Bot Node

Enterprise: Botnet Node Sources

Enterprise: Botnet Node Targets

Enterprise Top 5

Source Countries

  • China flag China
  • India flag India
  • United States flag United States
  • Russia flag Russia
  • Vietnam flag Vietnam

Targeted Countries

  • Brazil Brazil
  • Brazil Brazil
  • Vietnam Vietnam
  • Nicaragua Nicaragua
  • Saudi Arabia Saudi Arabia

Targeted Industries

  • Wireless Telecommunications Carriers (except Satellite) Wireless Telecommunications Carriers (except Satellite)
  • Plumbing Heating and Air-Conditioning Contractors Plumbing Heating and Air-Conditioning Contractors
  • Wired Telecommunications Carriers Wired Telecommunications Carriers
  • Educational Support Services Educational Support Services
  • Software Publishers Software Publishers

Service Provider

345,740
Number of ddos attacks
370,989
number of bots
27
max vector count in a single attack

Service Provider: Botnet Node Sources

Service Provider: Botnet Node Targets

Service Provider Top 5

Source Countries

  • China flag China
  • India flag India
  • Russia flag Russia
  • United States flag United States
  • Brazil flag Brazil

Targeted Countries

  • United States United States
  • China China
  • Netherlands Netherlands
  • Vietnam Vietnam
  • Chile Chile

Targeted Industries

  • Computing Infrastructure Providers Data Processing Web Hosting and Related Services Computing Infrastructure Providers Data Processing Web Hosting and Related Services
  • Wired Telecommunications Carriers Wired Telecommunications Carriers
  • Wireless Telecommunications Carriers (except Satellite) Wireless Telecommunications Carriers (except Satellite)
  • All Other Telecommunications All Other Telecommunications
  • Insurance Agencies and Brokerages Insurance Agencies and Brokerages

Active DDoS Botnet Nodes