Tuesday , April 1 2025

US, India and China Most Targeted in DDoS Attacks, StormWall Q1 2023 Report

StormWall projects a 170% increase in DDoS Attacks by the end of 2023 and urges businesses to implement mitigation strategies.

Leading cybersecurity provider, StormWall, has released a comprehensive report on the state of Distributed Denial of Service attacks (DDoS attacks) in Q1 2023. The report, based on an analysis of attacks on StormWall’s clients across various sectors, reveals a significant increase of 47% in DDoS attacks compared to the same period last year.

The findings, shared with Hackread.com, highlight a worrisome trend of botnet usage and a growing practice of smokescreening to conceal multi-vector attacks.

CVE-2025-1268
Patch urgently! Canon Fixes Critical Printer Driver Flaw

Canon has announced a critical security vulnerability, CVE-2025-1268, in printer drivers for its production printers, multifunction printers, and laser printers....
Read More
CVE-2025-1268  Patch urgently! Canon Fixes Critical Printer Driver Flaw

Within Minute, RamiGPT To Escalate Privilege Gaining Root Access

RamiGPT is an AI security tool that targets root accounts. Using PwnTools and OpwnAI, it quickly navigated privilege escalation scenarios...
Read More
Within Minute, RamiGPT To Escalate Privilege Gaining Root Access

Australian fintech database exposed in 27000 records

Cybersecurity researcher Jeremiah Fowler recently revealed a sensitive data exposure involving the Australian fintech company Vroom by YouX, previously known...
Read More
Australian fintech database exposed in 27000 records

Over 200 Million Info Leaked Online Allegedly Belonging to X

Safety Detectives' Cybersecurity Team found a forum post where a threat actor shared a .CSV file with over 200 million...
Read More
Over 200 Million Info Leaked Online Allegedly Belonging to X

FBI investigating cyberattack at Oracle, Bloomberg News reports

The Federal Bureau of Investigation (FBI) is probing the cyberattack at Oracle (ORCL.N), opens new tab that has led to...
Read More
FBI investigating cyberattack at Oracle, Bloomberg News reports

OpenAI Offering $100K Bounties for Critical Vulns

OpenAI has increased its maximum bug bounty payout to $100,000, up from $20,000, to encourage the discovery of critical vulnerabilities...
Read More
OpenAI Offering $100K Bounties for Critical Vulns

Splunk Alert User RCE and Data Leak Vulns

Splunk has released a security advisory about critical vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These issues could lead...
Read More
Splunk Alert User RCE and Data Leak Vulns

CIRT alert Situational Awareness for Eid Holidays

As the Eid holidays near, cybercriminals may try to take advantage of weakened security during this time. The CTI unit...
Read More
CIRT alert Situational Awareness for Eid Holidays

Cyberattack on Malaysian airports: PM rejected $10 million ransom

Operations at Kuala Lumpur International Airport (KLIA) were unaffected by a cyber attack in which hackers demanded US$10 million (S$13.4...
Read More
Cyberattack on Malaysian airports: PM rejected $10 million ransom

Micropatches released for Windows zero-day leaking NTLM hashes

Unofficial patches are available for a new Windows zero-day vulnerability that allows remote attackers to steal NTLM credentials by deceiving...
Read More
Micropatches released for Windows zero-day leaking NTLM hashes

The study reveals that attackers are increasingly targeting critical infrastructure and services, including logistical services, payment processing hubs, and banking systems, in an attempt to impact a larger number of users. The average attack strength reached a peak of 1.4 Tbps, and the longest attack lasted for 4 days.

Among the sectors targeted, the financial industry experienced the highest number of attacks, accounting for 34% of the total and witnessing a staggering 68% increase compared to Q1 2022. E-commerce also faced significant challenges, enduring 22% of the attacks and experiencing a 51% increase from the previous year. Telecommunications remained a popular target, with 16% of the attacks and a 47% year-over-year increase.

The use of botnets in DDoS attacks continues to gain traction, with over 38% of attacks leveraging networks of compromised devices. Additionally, the practice of smokescreening, where DDoS attacks are used as decoys in multi-vector assaults, increased by 28% compared to the previous year.

The report also reveals that more destructive HTTP attacks are becoming increasingly accessible to run. As a result, 82.3% of DDoS attacks targeted the application layer (L7), while 11.7% were directed at the transport (L4) and network (L3) layers of the OSI model. DNS was targeted in 2.3% of the attacks, and the remaining 3.7% were aimed at other targets.

Geographically, the United States (17.6% attack share), India (14.2%), and China (11.7%) remain the most targeted countries. However, the United Arab Emirates saw a notable surge in attacks, with the proportion nearly doubling from 3.8% in Q1 2022 to 6.4% in the current year. Russia and Ukraine, on the other hand, experienced a decline in DDoS activity as hacktivism subsided.

Did you know that in 2021, the United States and China both held the position of being the top countries with the most exposed cloud servers due to misconfiguration? India ranked fifth in this regard. Read more…

US, India and China Most Targeted in DDoS Attacks, StormWall Q1 2023 Report
Targeted industries and countries

StormWall’s report emphasizes the escalating threat of DDoS attacks, as evidenced by the significant rise in attack volume, strength, and duration. With threat actors constantly adapting their tactics and integrating DDoS attacks within multi-vector incidents, organizations need to address not only outages from overburdened servers but also data breaches, ransomware, and other associated threats.

Based on data analysis from client-targeted attacks, StormWall projects a further 170% increase in DDoS attacks by the end of 2023. In light of these alarming findings, the company strongly recommends that all businesses seek professional DDoS protection to safeguard their online assets in the upcoming year.

Check Also

Singapore

Singapore issues new guidelines for data center and cloud services

The Infocomm Media Development Authority (IMDA of Singapore unveils advisory guidelines to reduce occurrences of …

Leave a Reply

Your email address will not be published. Required fields are marked *