The "DDoS for hire" market is booming. Even a schoolboy can now bring down the website of a large company.

MOON ADM

Well-known member
Member
Joined
Jan 22, 2026
Messages
101
Reaction score
923
Experts have recognized that attacking complex systems has become frighteningly easy.

1771873503084.png

The latest Radware Global Threat Analysis Report describes 2025 as a turning point for cyber threats. According to the company, the attackers simultaneously increased the power of network DDoS attacks and increased pressure on web applications and APIs, while automation based on generative AI lowered the entry threshold for attacks.

Radware records the return of large-scale network DDoS with a record of 29.7 Tbps, which was associated with the Aisuru botnet. The report also mentions Kimwolf and the growth of the "DDoS for hire" market, which has made multi-terabit attacks more accessible to less prepared participants. On average, in the second half of 2025, one Radware customer faced more than 25,351 DDoS attacks, which translates to about 139 per day, and the overall DDoS growth year-on-year was 168.2%. Among the network vectors, UDP floods accounted for half of the reflected volume, and North America was the leader in geography with a share of 63.1%.

At the same time, the proportion of "short" incidents increased. The report says that most of the record attacks lasted less than a minute, which is why manual response scenarios stop working. At the same time, "normal" attacks in the range of 100-500 Gbit/s took about 10 hours on average, while multi-terabit attacks took about 35 minutes.

Radware estimates that the most sensitive impacts are increasingly at the application level. The Cloud Application Protection service recorded a 128% increase in malicious transactions compared to 2024, with vulnerability exploitation attempts accounting for the largest share — 41.8%.

There was a separate surge in such attacks in the fourth quarter, which the authors linked to the active "arming" of new CVEs, including React2Shell (CVE-2025-55182). The activity of malicious bots increased by 91.8% over the year, and North America became the main destination for attacks on web applications and APIs with a share of 73.7% of transactions.

A separate section of the report is devoted to the problem of identification of AI agents. Radware points out that platforms have to allow automated POST requests for "useful" agents, and this opens the way for their identity to be replaced. The company considers approaches that use cryptographic signatures or DNS and IP range verification to be more stable, and schemes tied to the User-Agent string, which is easy to forge, to be less reliable. In this context, scenarios of hidden data output through "zero click" and indirect injection of hints are described, including ShadowLeak and ZombieAgent, where compromise can be fixed through the agent's long-term memory.

Against the background of geopolitical events, a wave of hacktivism persists. Radware estimated the number of unique DDoS claims in Telegram in 2025 at about 16,000, and named the pro-Russian group NoName057(16) with 4,692 claims as the most active association. Keymous+, Hezi Rash, Mr. Hamza, Anonymous VNLBN and RipperSec are also among the frequently mentioned participants, while Israel, the United States and Ukraine were among the most attacked countries.
 
5,643Threads
75,600Messages
5,827Members
trocryptdirector1Latest member
Top Bottom