
China
The DDoS threat landscape is constantly evolving, and to stay ahead of adversaries, ongoing monitoring and analysis are essential to detect how they are modifying their behavior and targets. NETSCOUT monitors the global threat landscape and drills into regional and country-level statistics to ensure that adversaries inform us of near-real-time trends. The country-level analytics featured on this page are automatically generated using our global threat analysis and collection platform, ATLAS, and provide a range of benchmarks for the specified time period, such as the top vectors used in DDoS attacks, top targeted industries, largest attack by bandwidth and throughput, most vectors used in an attack, and total attack frequency.
Max Multivector Attack
Max number of vectors seen in a single attack
21
Attack Vectors Used
1. COAP Amplification
2. DNS Amplification
3. ICMP
4. MS SQL RS Amplification
5. NTP Amplification
6. NetBIOS Amplification
7. RIPv1 Amplification
8. SNMP Amplification
9. SSDP Amplification
10. STUN Amplification
11. TCP ACK
12. TCP RST
13. TCP SYN
14. UDP
15. WS-DD Amplification
16. chargen Amplification
17. mDNS Amplification
18. memcached Amplification
19. rpcbind Amplification
Top Attack Vectors
Ts
TCP SYN
Number of Attacks
92,740
Dn
DNS Amplification
Number of Attacks
24,674
Np
NTP Amplification
Number of Attacks
16,026
Ta
TCP ACK
Number of Attacks
7,721
Tr
TCP RST
Number of Attacks
3,609
Top Five Industries Under Attack
The following table lists the top vertical industries under attack from January 2025 to June 2025 by number of attacks.
Rank | Vertical | Frequency | Max Attack | Max Impact | Average Duration |
---|---|---|---|---|---|
1 |
|
65,078 | 483.25 Gbps | 45.11 Mpps | 24 Minutes |
2 |
|
34,767 | 539.41 Gbps | 47.24 Mpps | 30 Minutes |
3 |
|
14,922 | 480.97 Gbps | 42.12 Mpps | 25 Minutes |
4 |
|
2,626 | 143.54 Gbps | 12.58 Mpps | 28 Minutes |
5 |
|
1,593 | 346.53 Gbps | 30.38 Mpps | 20 Minutes |