


New findings reveal that the second quarter of 2025 experienced a significant increase in application-layer DDoS attacks, with financial institutions being the most frequently targeted.
These types of attacks focus on web applications and are difficult to distinguish from normal traffic, as they often mimic legitimate user behavior. Experts at Qrator Labs reported a 74% increase in such attacks compared to the same period in 2024.
Due to their dependence on continuous digital operations and instant online transactions, financial institutions suffered 43.6% of these attacks. E-commerce companies were targeted in 22.6% of cases, while ICT service providers accounted for 18.2%.
In addition, Q2 2025 witnessed the appearance of the largest DDoS botnet ever documented, comprising 4.6 million compromised devices. For comparison, this is over 3.5 times larger than the prior record and nearly 20 times bigger than the biggest botnet seen throughout 2024.
“This sudden surge in application-layer DDoS attacks is directly linked to the growing number of vulnerable devices with high-speed internet access,” explained Andrey Leskin, chief technology officer at Qrator Labs.
“The scale of botnets we're witnessing now would have been unthinkable even a year ago. An attack from a botnet of this size, if not adequately managed, could produce tens of millions of requests, bringing online services to a standstill, causing transaction failures, and halting digital activities entirely."
DDoS attacks aimed at network and transport layers—layers 3 and 4—also grew more intense, with a 43% increase in attacks surpassing 1 Gbps compared to the same period last year.
The longest of these attacks was directed at online gaming platforms and lasted just over four days.
Common application layer DDoS attack techniques
At the application layer, layer 7, most attacks fell under the category of Request Rate Patterns.
The top three countries from which layer 7 DDoS attacks originated during the quarter remained unchanged from last year: Russia at 17%, the US at 16.6%, and Brazil at 13.2%.
Researchers also noted that the longest Layer 7 DDoS attack in Q2 2025 lasted for 65.5 hours.
Qrator Labs recommends that organizations strengthen their incident response strategies, invest in robust DDoS protection solutions, and perform regular stress tests on their infrastructure to build resilience.
"Not all DDoS protection providers are prepared to handle an attack of this scale, meaning even companies with existing defenses may not be ready for the consequences," warned Leskin.
Earlier this month, research conducted by Akamai Technologies and FS-ISAC, a cybersecurity group serving the financial industry, showed a 23% rise in application-layer DDoS attacks against financial institutions from 2023 to 2024.
The financial sector continued to be the primary target for volumetric DDoS attacks year after year, with a notable jump occurring in October 2024.
Stay updated by following php.cn on Google News for all our latest updates, expert insights, and in-depth coverage.
The above is the detailed content of Application layer DDoS attacks are skyrocketing – here's why. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

In what seems like yet another setback for a domain where we believed humans would always surpass machines, researchers now propose that AI comprehends emotions better than we do.Researchers have discovered that artificial intelligence demonstrates a

Artificial intelligence (AI) began as a quest to simulate the human brain.Is it now in the process of transforming the human brain's role in daily life?The Industrial Revolution reduced reliance on manual labor. As someone who researches the applicat

Like it or not, artificial intelligence has become part of daily life. Many devices — including electric razors and toothbrushes — have become AI-powered," using machine learning algorithms to track how a person uses the device, how the devi

A new artificial intelligence (AI) model has demonstrated the ability to predict major weather events more quickly and with greater precision than several of the most widely used global forecasting systems.This model, named Aurora, has been trained u

The more precisely we attempt to make AI models function, the greater their carbon emissions become — with certain prompts generating up to 50 times more carbon dioxide than others, according to a recent study.Reasoning models like Anthropic's Claude

Artificial intelligence (AI) models can threaten and blackmail humans when there’s a conflict between the model's objectives and user decisions, according to a new study.Published on 20 June, the research conducted by the AI firm Anthropic gave its l

The major concern with big tech experimenting with artificial intelligence (AI) isn't that it might dominate humanity. The real issue lies in the persistent inaccuracies of large language models (LLMs) such as Open AI's ChatGPT, Google's Gemini, and

The more advanced artificial intelligence (AI) becomes, the more it tends to "hallucinate" and provide false or inaccurate information.According to research by OpenAI, its most recent and powerful reasoning models—o3 and o4-mini—exhibited h
