29.7 Tbps DDoS Attack via Aisuru Botnet Breaks Internet with New World Record

The cybersecurity ecosystem faces a stark new reality: distributed denial-of-service attacks have escalated from catastrophic anomalies to a relentless operational hazard.

A devastating 29.7 terabit-per-second (Tbps) assault originating from the Aisuru botnet has shattered the previous 22 Tbps record, marking a critical inflection point in the battle for internet infrastructure resilience.

The Attack and Its Technical Anatomy

Cloudflare’s autonomous mitigation infrastructure successfully detected and neutralized the Aisuru-powered volumetric barrage within seconds, demonstrating that even record-breaking attack volumes can be contained through advanced filtering systems.

The assault achieved 14.1 billion packets per second through a UDP carpet-bombing technique that targeted approximately 15,000 destination ports simultaneously while randomizing packet characteristics to evade legacy filtering mechanisms and traditional scrubbing centers.

29.7 Tbps DDoS Attack
Volumetric DDoS attack (Source: Cloudflare)
Volumetric DDoS attack (Source: Cloudflare)

The sheer scale represents a qualitative shift in the threat environment. Where multi-terabit attacks once represented isolated, headline-grabbing incidents, they now constitute the normalized upper bound of attack sophistication.

The previous 22 Tbps threshold, quietly surpassed during Q3 2025, already signaled this transition yet Aisuru’s 29.7 Tbps demonstrates the trend’s momentum remains unbroken.

Record-Breaking DDoS Attack (Source: Cloudflare)
Record-Breaking DDoS Attack (Source: Cloudflare)

Cloudflare estimates Aisuru comprises between 1 and 4 million compromised devices globally, establishing it as the dominant botnet in the contemporary threat landscape.

More troublingly, portions of the botnet operate as a rental service, enabling would-be attackers to acquire sufficient capacity to saturate backbone links or incapacitate national-scale ISPs for only hundreds to thousands of dollars.

This commoditization of attack infrastructure democratizes the ability to launch devastating assaults, shifting DDoS from a specialized capability to a readily accessible, low-cost weapon.

Since early 2025, Cloudflare has mitigated 2,867 discrete Aisuru attacks, including 1,304 hyper-volumetric events during Q3 alone a 54 percent quarter-over-quarter surge translating to approximately 14 mega-attacks per day.

The velocity and frequency of these incidents underscore how thoroughly DDoS has embedded itself in the baseline threat model.

The attack spike extends far beyond Aisuru’s individual campaigns. Cloudflare’s Q3 2025 threat telemetry reveals 8.3 million blocked DDoS attacks across its platform a 15 percent quarterly increase and 40 percent year-over-year jump.

Year-to-date totals have reached 36.2 million attacks, already representing 170 percent of the entire 2024 volume with one quarter remaining.

Network-layer assaults comprised 71 percent of all Q3 DDoS incidents, surging 87 percent quarter-over-quarter and 95 percent year-over-year, signaling attackers’ tactical pivot away from application-layer complexity toward raw bandwidth exhaustion.

Conversely, HTTP-layer attacks declined 41 percent quarter-over-quarter and 17 percent year-over-year, indicating a deliberate shift in adversary methodology.

The extremes have become exponentially more extreme. Incidents exceeding 100 million packets per second jumped 189 percent quarter-over-quarter, while attacks surpassing 1 Tbps grew 227 percent.

Yet paradoxically, most of these assaults terminate within 10 minutes a window too compressed for manual response or traditional on-demand mitigation contracts to reliably intervene.

Attack geography now mirrors geopolitical flashpoints with striking precision. Indonesia remains the predominant global source of DDoS traffic, having logged a 31,900 percent increase in HTTP-based DDoS requests since 2021.

Q3 2025 witnessed dramatic activity surges in the Maldives, France, and Belgium nations simultaneously experiencing mass street-level unrest, including the Maldivian “Stop the Loot!” movement, France’s “Block Everything” strikes, and large-scale Gaza solidarity demonstrations in Brussels.

China remained the most-targeted nation, followed by Turkey and Germany, while the United States climbed into fifth place and the Philippines posted the largest rise within the top 10.

The Philippines’ ascent underscores how contemporary DDoS campaigns track not solely technical opportunity but geopolitical conflict, public sentiment, and regulatory tensions surrounding artificial intelligence and trade policy.

Sectoral targeting reflects similar geopolitical currents. Telecommunications providers, gaming platforms, hosting companies, and financial services firms consistently appear in adversaries’ crosshairs.

Generative AI providers experienced a particularly acute spike, with attacks escalating up to 347 percent month-over-month in September alone. Mining, minerals, metals, and automotive sectors simultaneously surged in response to escalating European Union-China trade tensions over rare earth elements and electric vehicle tariffs.

The Aisuru botnet’s scale extends beyond intended targets. KrebsOnSecurity reports that substantial portions of the botnet’s traffic have inflicted unintended disruptions across major U.S. internet service providers collateral damage reflecting both the attack’s sheer magnitude and the difficulty of surgical precision at multi-terabit scales.

Cloudflare’s successful mitigation of the 29.7 Tbps assault demonstrates that modern distributed defense architectures can withstand extreme volumetric onslaughts.

However, the cadence of attacks averaging 14 mega-incidents daily in Q3 combined with their sub-10-minute duration, reveals a defensive dilemma: infrastructure must remain vigilant against threats that manifest and dissipate faster than conventional incident response protocols can mobilize.

The age of multi-terabit DDoS has arrived not as a future concern but as an embedded operational reality.

Organizations must recalibrate their defensive posture accordingly, recognizing that yesterday’s anomalies have become today’s baseline threats.

Find this Story Interesting! Follow us on Google NewsLinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories