Security 16 min read

The 31 Tbps Era: What Record-Breaking Botnets Mean for Your DDoS Posture

The record number got the headlines. The 35 seconds is the story. Hyper-volumetric attacks are now bigger than any scrubbing center, shorter than any escalation path, and cheaper to rent than a conference ticket, and the posture that survives them has no human in the loop.

By Ruslan Cherniak

In the closing days of December 2025, during a holiday attack campaign Cloudflare would later name The Night Before Christmas, the largest distributed denial-of-service attack ever recorded arrived on its network, peaked at 31.4 terabits per second, and was gone 35 seconds later. According to the disclosure, the attack was detected and mitigated automatically, without so much as an internal alert. The defenders read about it in their own telemetry. The attackers, most likely, typed one command into a botnet control panel and walked away.

Sit with that for a second. The biggest attack in the history of the internet did not wake anyone up. Not because it was small, but because both sides of the exchange were machines, and the humans on the defending side had already made their only meaningful decision months earlier, when they chose an architecture that absorbs this class of event automatically.

That is the actual lesson of the 31 Tbps era, and it is why I think the record number, the one in every headline, is close to the least important number in the report. Records are trivia. What should change your architecture is the shape of the thing: attacks are now routinely bigger than any scrubbing facility’s dedicated capacity, shorter than any escalation path, launched dozens of times a day, and rentable by anyone with fifty dollars. Every one of those properties points at the same conclusion about posture, and it is not a comfortable one for teams still running detect-then-divert.

The short version: the DDoS record went from 5.6 Tbps to 31.4 Tbps in fourteen months, and the record-setting attack lasted 35 seconds. Cloudflare mitigated 47.1 million attacks in 2025, triple the network-layer volume of 2024, and Radware’s average customer absorbed 139 network-layer attacks per day in the second half of the year. The botnet behind the record, Aisuru and its Kimwolf sibling, runs on compromised Android TV boxes and drives roughly a third of global DDoS attack traffic. The US Department of Justice disrupted it in March 2026; a successor botnet was observed recruiting Android TVs the day before the takedown was announced. Attack duration collapsed to an 8.9-minute average, with most high-impact bursts under a minute. No human process operates on that timescale. The posture that holds is always-on absorption at the edge, sized in hundreds of terabits, covering whole prefixes and DNS rather than a few hostnames, with the runbook rewritten for events that end before a phone finishes ringing.


The record lasted 35 seconds

It helps to see the whole ladder, because the slope is the point.

The record entering 2025 was 5.6 Tbps, a Mirai-variant attack from late October 2024 that Cloudflare disclosed in January. In May 2025 it became 7.3 Tbps, an attack that delivered 37.4 terabytes in about 45 seconds. September brought 11.5 Tbps and then, before the month was out, 22.2 Tbps, a burst that also set a packet-rate record above 10 billion packets per second and lasted roughly 40 seconds. In early December, Cloudflare disclosed a 29.7 Tbps attack that had actually occurred back in the third quarter and lasted 69 seconds. And in the closing days of the year: 31.4. Six records in fourteen months, a 5.6x increase, and not one of the attacks behind them lasted two full minutes.

The December record did not arrive alone. Cloudflare’s Q4 2025 threat report describes the campaign around it, which began on Friday, December 19: 902 hyper-volumetric attacks in the following weeks, roughly 53 per day, peaking at 9 billion packets per second and 205 million HTTP requests per second. Telecom providers took the worst of it, alongside IT services, gaming, and gambling platforms. For the full year, Cloudflare counted 47.1 million DDoS attacks, about 5,376 every hour, with network-layer attacks tripling from 11.4 million in 2024 to 34.4 million. Attacks above 1 Tbps grew more than 700% compared to late 2024. Radware’s numbers from its own customer base point the same direction: network-layer DDoS up 168.2% year over year, with 63.1% of it aimed at North America.

One comparison puts the physics in perspective. Akamai’s Prolexic, one of the most battle-tested dedicated scrubbing platforms in the industry, advertises 20+ Tbps of dedicated defense capacity across 32 scrubbing centers. That is real capacity that has stopped record attacks for two decades, and a single burst in December 2025 exceeded it by more than half again. The era in which a dedicated scrubbing footprint could outweigh the largest single attack is over. What still outweighs the attack is distributed edge capacity, the aggregate of thousands of points of presence, which is measured in the hundreds of terabits. This is the same architectural argument we made in our piece on the security-performance trade-off, arriving from a different direction: the edge is no longer just where mitigation is convenient. It is the only place the arithmetic works.


A botnet made of television boxes

The thing generating these numbers is worth understanding, because its economics explain why the takedown that followed changed less than expected.

Aisuru and Kimwolf are closely related botnets, possibly independently operated, built primarily on compromised off-brand Android TV boxes, along with the usual routers, DVRs, and cameras. Cloudflare estimated the infected population at 1 to 4 million hosts. Arelion, which watches this from the vantage point of one of the largest internet backbones, attributed roughly 33% of global DDoS attack traffic to Aisuru in its July 2026 report, with individual attacks crossing its backbone at more than 1 Tbps on a routine basis.

A television box is a nearly ideal DDoS soldier. It sits on residential broadband, which has gotten fast enough that a few million homes aggregate into terabits. It is always on. Its owner will never patch it, never notice it, and never receive a security advisory for it, because the vendor that shipped it may not formally exist. And its traffic originates from the same residential IP space as paying customers, which is exactly the property that makes cheap IP-reputation filtering useless. The operators lean into that: infected devices have been tunneled through commercial residential proxy networks, blending attack infrastructure into the gray market for “clean” IP addresses.

Then there is the storefront problem. Nobody is stockpiling this capacity for some future cyberwar. It earns its keep by the day, and DDoS-for-hire services in the current market advertise attacks above 1 Tbps for under $50 a day. Radware and Arelion both flagged the same multiplier in their 2026 reports: AI tooling has lowered the skill floor for building and operating attack infrastructure, so the barrier to entry now is not knowledge. It is a cryptocurrency payment roughly the price of a restaurant dinner. When a capability is rentable at that price, the question “who would attack us?” loses most of its screening value. The honest answer is: anyone with a grievance, a ransom template, or a competitor’s flash sale to ruin.


The takedown worked for a day

If the supply side is the problem, the obvious answer is to take the botnet down. In March 2026, that is what happened. The US Department of Justice, working with German and Canadian authorities, announced the disruption of four botnets: Aisuru, Kimwolf, JackSkid, and Mossad, roughly 3 million infected devices in total. Lumen’s Black Lotus Labs null-routed nearly a thousand command-and-control servers. Court documents credited Aisuru alone with more than 200,000 attack commands.

Here is the detail that should calibrate your expectations. On March 18, one day before the announcement, Nokia Deepfield researchers documented a new Mirai-derived botnet actively recruiting tens of thousands of Android TV devices, installing persistence, and aggressively deleting competing malware from the hosts it claimed. The vulnerable device population did not shrink on takedown day. It just changed landlords.

None of this makes takedowns pointless. They impose real costs, burn real infrastructure, and the March action visibly disrupted the ecosystem for a while. But a takedown is demand suppression, and the supply of insecure devices keeps growing underneath it. The structural fix on the supply side is regulatory, and it finally has dates attached: the EU’s Cyber Resilience Act starts requiring manufacturers to report actively exploited vulnerabilities on September 11, 2026, next month as I write this, with the main security obligations applying from December 11, 2027. That is genuine progress, and it is also years away from mattering: it applies to products placed on the EU market going forward, and the tens of millions of unpatchable boxes already sitting under televisions will keep serving whoever compromises them until they die of old age. Realistically, the gap between takedowns that buy weeks and regulation that pays off in device generations is the period your architecture has to cover. Plan for it to last into the 2030s.


Your runbook has a reaction time. The attacks no longer do.

Now put the classic mitigation model against the current attack shape, step by step, because the mismatch is the whole argument.

Detect-then-divert works like this: monitoring notices an anomaly, which takes a detection window measured in minutes; someone or something decides it is an attack; traffic gets rerouted to a scrubbing facility, typically via a BGP announcement that takes time to propagate across the internet’s routing tables; scrubbed traffic returns through a tunnel. Under ideal automation this cycle runs in low minutes. With a human approving the diversion, which is still standard practice at plenty of enterprises because diversion has side effects, it runs in tens of minutes. That model was rational when attacks built gradually and lasted hours.

Against that, the 2026 duration data. Arelion measured the average attack at 8.9 minutes, down 20% year over year. During the December campaign, more than half the attacks lasted one to two minutes, and only 6% ran longer than two. Radware found most high-impact web DDoS attacks now finish inside 60 seconds. One mid-year dataset from Flowtriq, a smaller mitigation vendor, puts 86.5% of first-half 2026 attacks at under 60 seconds; treat any single vendor’s telemetry as a sample rather than a census, but every sample points the same way. The record itself, remember, lasted 35 seconds.

The arithmetic is not subtle. If the attack ends in 35 seconds and your mitigation path takes five minutes, your mitigation did not participate in the event. Every user-facing consequence, the failed checkouts, the timed-out logins, the API errors cascading into your mobile app, happened in full. And because short bursts arrive in volume, 139 network-layer attacks a day for Radware’s average customer, the failure repeats daily, each one individually too short to page anyone and collectively expensive. There is a second-order cost we see in postmortems: teams burn hours investigating brownouts that were sub-minute floods nobody classified, or worse, attribute a self-inflicted traffic spike to an attack and start fighting the wrong fire.

Attackers know all of this. The short burst is not a limitation of their tooling; it is the product. It maximizes disruption per unit of botnet exposure, evades diversion entirely, and doubles as reconnaissance: a 40-second probe tells the operator exactly how your defenses respond, at nearly zero cost, before a longer campaign.

Three horizontal timelines compared against the same 35-second attack window, drawn on a dark background. The top timeline shows the attack itself: traffic ramps from zero to a 31.4 terabit per second peak in about fifteen seconds, holds briefly, and is finished by second 35. The middle timeline shows a detect-and-divert defense: the detection threshold trips at around one to two minutes, a human approves diversion several minutes later, a BGP route change propagates, and scrubbing finally engages somewhere between five and fifteen minutes, long after the attack has ended, with the entire damage window shaded to show that users absorbed the full impact. The bottom timeline shows an always-on edge posture: filtering is already inline when the first malicious packet arrives at second zero, absorption happens continuously across thousands of points of presence during the burst, and the event closes with no human action, the damage window reduced to almost nothing. A caption underneath reads: the attack no longer waits for your escalation path, so protection has to be in the path before the attack starts.


What the record headlines get wrong

Having spent half this essay on the giant numbers, honesty requires the counterweight: if you optimize your posture purely for the biggest burst, you will still get hurt, just differently. Three corrections to the headline narrative.

Most attacks are small, and the sophisticated ones are small on purpose. Akamai’s security team published a piece last September on what it calls Distributed Denial of Defense, with a sentence worth pinning above any capacity-planning spreadsheet: “Sophisticated DDoS attacks are almost never high in volumetric terms.” A capable adversary would rather quietly probe your defense stack for the weak seam, the unprotected secondary DNS, the API subdomain that bypasses the WAF, the appliance that falls over at a modest packet rate, than announce themselves with terabits. In Radware’s data, 94.4% of web DDoS attacks measured under 100,000 requests per second. The record tells you the ceiling. The median tells you your Tuesday.

Attacks got wider, not just taller. More than 30% of the attacks Prolexic mitigated in Q2 2025 were horizontal, spread across many destinations at once, and 2025 saw carpet-bombing campaigns hitting tens of thousands of IP addresses across entire prefixes. A posture that protects twelve important hostnames and leaves the rest of the address space naked is exactly what carpet bombing exists to exploit. Multi-vector composition keeps climbing too, with combined network- and application-layer floods in the same event.

And a sourcing caveat that applies to this essay as much as anything you will read on the subject: attack records are disclosed by the vendors that mitigated them. The numbers above come from Cloudflare, Radware, Arelion, Akamai, and Nokia Deepfield because those are the entities positioned to measure, and each sees the internet from its own angle. The figures agree directionally, which is why I am comfortable building an argument on them, but nobody audits these disclosures, and marketing incentive and measurement live in the same building. Weight accordingly.


What an always-on posture looks like in 2026

If the attack shape is short, wide, frequent, and occasionally enormous, the posture requirements fall out almost mechanically. Here is what we now consider the baseline when we review a client’s DDoS standing, and none of it is exotic.

Mitigation must already be in the path. Anything that begins with “detect, then” concedes the first minutes, and the first minutes are now the whole attack. Always-on absorption at the network edge, where anycast spreads the burst across thousands of points of presence and filtering happens inline, is the only model whose reaction time is zero. This is capacity you rent rather than build; the Akamai edge we deploy for clients aggregates over 700 Tbps across 4,000+ locations, a number that only makes sense as a shared, distributed pool. For workloads with special routing or compliance constraints, dedicated scrubbing still matters, and Akamai’s own guidance is blunt about preferring dedicated defense capacity over shared CDN capacity for critical infrastructure, with Prolexic now offered in cloud, on-prem, and hybrid forms with a zero-second mitigation SLA. The dedicated-versus-shared question is legitimately situational. What is no longer situational is always-on versus on-demand.

Cover the prefix, not the poster children. Carpet bombing made per-hostname protection a half-measure. The review question is simple to ask and uncomfortable to answer: what fraction of your routable address space, including the VPN concentrators, mail relays, SFTP endpoints, and that forgotten staging subnet, sits behind always-on mitigation? Attackers enumerate; the December campaign’s victims included plenty of infrastructure nobody considered a target.

Treat DNS as its own front. Authoritative DNS is the dependency that turns a partial outage into a total one, it answers from a small set of well-known addresses, and it is a favorite of exactly the botnets discussed here. If your DNS runs on the same undersized appliance estate it did in 2021, the 31 Tbps era will find it.

Keep the origin unreachable. Edge absorption is worthless if the attacker can locate and hit your origin directly, and origin exposure remains the most common critical finding in our audits, usually via a stale DNS record or an overly chatty certificate. We covered the mechanics in our CDN misconfiguration field guide, and it is the mistake in that list with the highest blast radius.

Mind the application layer’s price tag. An HTTP flood at 200 million requests per second threatens more than availability, because every per-request security control on your stack bills you for the privilege of being attacked. We priced the challenge-page failure mode in an earlier post, and the short version is that a defense that charges you per request is, under flood conditions, part of the attack surface.

Rewrite the runbook for 35 seconds. Take your current incident flow and walk it against a burst that starts, peaks, and ends inside a minute, then repeats at random intervals all week. Every step that involves a phone call, a ticket, an approval, or a BGP change fails that test. What survives is preparation: pre-authorized automated responses, thresholds tuned in advance, post-event forensics instead of mid-event heroics, and drills. The FS-ISAC and Akamai DDoS maturity model is a reasonable public benchmark for where you sit; most organizations we assess land lower than they expect, not because they lack tooling but because their process still assumes a human gets to participate.

Whether you run this yourself or with a partner is the same build, buy, or partner decision as the rest of your security estate, with one wrinkle: DDoS is the discipline where capacity is least buildable. Nobody provisions 30 Tbps of headroom for an event that lasts half a minute. Everyone rents it, and the meaningful choices are whose network, always-on or not, and who tunes it.


The numbers that make the argument

Six measurements, most obtainable inside a month, that convert this from an opinion into a decision.

  • Time to mitigate, measured from first malicious packet, not from detection. If those two timestamps differ by minutes, that difference is your users’ outage, and no SLA that starts counting at detection will show it.
  • Attacks absorbed versus attacks noticed. Pull twelve months of edge and provider logs and count sub-five-minute events nobody triaged. This number reframes “we rarely get attacked” into what it usually is: “we rarely see it.”
  • Prefix coverage. The percentage of your routable address space behind always-on mitigation. Anything below roughly 100 has a carpet-bombing story waiting.
  • DNS resilience, tested rather than asserted. Peak query-per-second capacity of your authoritative estate against a simulated flood, and whether a failure degrades or severs.
  • Origin reachability from a cold start. Whether a competent outsider can find a path to origin that bypasses the edge. Binary, and decisive.
  • Cost per absorbed event. Standing mitigation cost divided by absorbed attacks. In 2024 this figure argued for on-demand scrubbing; at 139 network-layer attacks a day against the average large network, it now argues the other way, and it is the line item that gets a CFO to fund the fix.

Where the curve goes next

The extrapolation everyone wants is the irresponsible one, so let me be careful with it. The record grew 5.6x in fourteen months. Straight-line thinking says a 100 Tbps burst arrives sometime in 2027. I would not sign my name to the number, because the curve depends on residential bandwidth growth, on whether the post-takedown botnet consolidation produces one dominant successor or several competing ones, and on how quickly device regulation bites. But I will sign my name to the direction, and so, implicitly, do the CRA’s drafters, whose device-security obligations land December 2027 and start improving the hardware population years after that. Terabit-class bursts are becoming background radiation. At some point in the next two years, a 20 Tbps attack will not be news, in the way a 500 Gbps attack stopped being news around 2023.

Two quieter trends are worth more of your attention than the record chase. Vector churn is accelerating: mid-2026 telemetry shows reflection techniques rising and falling within quarters, which rewards platforms that update filters globally over appliances that wait for firmware. And both sides are automating judgment, not just volume. The botnets probe defenses and rotate tactics; the defenses tune thresholds and classify traffic without operators. The December record, mitigated with no internal alert, was two automated systems resolving a conflict in 35 seconds while everyone slept. That is not a fluke of one incident. It is what this discipline now is, and the only question your organization gets to answer is which side of it has better machines.

The uncomfortable audit question is no longer “could we survive the record?” Almost nobody needs to survive 31.4 Tbps aimed at them specifically. The question is whether last Tuesday’s 40-second, 80 Gbps burst reached your origin, whether anyone can say so with evidence, and whether the answer would be the same for every prefix you announce. If those answers take longer than a day to produce, that is the finding.

Let's plan your next move.

A 30-minute consultation with one of our senior architects. Walk away with a clear, vendor-neutral assessment of your security and performance posture.

Read our case studies