29.7 Tbps DDoS Attack Via Aisuru Botnet Breaks Internet With New World Record
A recent distributed denial-of-service (DDoS) attack, peaking at 29.7 terabits per second (Tbps), was launched by the Aisuru botnet, setting a new benchmark for attack volume. This event highlights the susceptibility of core internet infrastructure to…
A recent distributed denial-of-service (DDoS) attack, peaking at 29.7 terabits per second (Tbps), was launched by the Aisuru botnet, setting a new benchmark for attack volume. This event highlights the susceptibility of core internet infrastructure to extreme load conditions.
Previously, a 22 Tbps attack was the highest recorded. However, the current incident emphasizes the increasing frequency of multi-terabit attacks, as detailed in Cloudflare's latest DDoS threat report.
The attack employed a UDP “carpet bombing” technique, targeting approximately 15,000 destination ports per second and using randomized packet attributes to evade static filtering and legacy scrubbing centers. Despite its scale, Cloudflare's autonomous mitigation stack effectively detected and filtered the traffic in seconds, ensuring uninterrupted service for the target.
The Aisuru botnet is estimated to consist of approximately 1–4 million compromised devices globally, positioning it as a significant threat in the current ecosystem. In 2025, Cloudflare mitigated 2,867 attacks from Aisuru, including 1,304 hyper-volumetric events in Q3, reflecting a 54% increase from the previous quarter.
Portions of the botnet are available for hire, allowing attackers to rent capacity to disrupt backbone links or national ISPs at relatively low costs.
This event highlights the susceptibility of core internet infrastructure to extreme load conditions.
In Q3 2025, Cloudflare blocked 8.3 million DDoS attacks, marking a 15% increase quarter-over-quarter and a 40% increase year-over-year. The year-to-date total reached 36.2 million attacks, significantly surpassing the full-year 2024 volume.
Network-layer DDoS attacks accounted for approximately 71% of all attacks in the quarter, with a notable rise in incidents exceeding 100 million packets per second and those above 1 Tbps.
Cloudflare’s telemetry indicates that DDoS attacks frequently target telecommunications providers, gaming platforms, hosting companies, and financial services, with information technology and telecoms being the most attacked industries in Q3. Generative AI providers, mining, and automotive sectors also experienced significant increases in attacks.
Attack geography shifts in response to geopolitical tensions, with Indonesia noted as a leading source of DDoS traffic. The Maldives, France, and Belgium experienced significant increases in DDoS activity due to local unrest and protests.
China remained the most-targeted country, followed by Turkey and Germany. The United States moved to fifth place, with the Philippines experiencing the largest rise within the top 10 most-targeted countries, correlating with geopolitical and regulatory conflicts.
Based on reporting by Cyber Security News.
