Cloudflare Blocks Record-Breaking 31.4 Tbps DDoS Attack in Night Before Christmas Campaign
Cloudflare Blocks Record-Breaking 31.4 Tbps DDoS Attack in “Night Before Christmas” Campaign
The Aisuru/Kimwolf botnet launched what Cloudflare describes as the largest DDoS attack ever publicly disclosed, peaking at 31.4 Terabits per second (Tbps) during a coordinated assault that lasted just 35 seconds in late 2025.[1][2] The attack, part of a broader campaign dubbed “The Night Before Christmas,” represents an alarming escalation in the scale and sophistication of distributed denial-of-service threats targeting critical internet infrastructure.
The Attack: Unprecedented Scale and Sophistication
The Aisuru/Kimwolf botnet initiated its assault on December 19, 2025, targeting Cloudflare’s infrastructure and its customers with hyper-volumetric HTTP DDoS attacks exceeding 20 million requests per second.[1][2] Over 94% of the attacks delivered between one and five billion packets of unwanted traffic per second, with 58% lasting between one and two minutes.[1]
The campaign comprised 902 hyper-volumetric DDoS attacks across three categories: 384 packet-intensive attacks, 329 bit-intensive attacks, and 189 request-intensive attacks, averaging 53 attacks per day.[2] During the campaign, the average attack size reached 3 billion packets per second (Bpps), 4 Tbps, and 54 million requests per second (Mrps), with maximum rates touching 9 Bpps, 24 Tbps, and 205 Mrps.[3]
The botnet’s capabilities are formidable: it is capable of launching DDoS attacks that can cripple critical infrastructure, crash most legacy cloud-based DDoS protection solutions, and even disrupt the connectivity of entire nations.[2] The attack infrastructure itself reveals a troubling trend—cloud computing providers including DigitalOcean, Microsoft, Tencent, Oracle, and Hetzner were identified as the largest sources of DDoS attacks, demonstrating how easily-provisioned virtual machines enable high-volume assaults.[1]
The Impact: A Year of Explosive Growth
The “Night Before Christmas” campaign represents only a fraction of a much larger threat landscape. DDoS attacks surged by 121% in 2025, with Cloudflare mitigating an average of 5,376 attacks every hour—comprising 3,925 network-layer attacks and 1,451 HTTP DDoS attacks.[2][3] The total number of DDoS incidents reached 47.1 million in 2025, more than doubling from previous years.[3]
Hyper-volumetric attacks have become particularly prevalent, growing by 700% compared to late 2024.[2] In the fourth quarter of 2025 alone, hyper-volumetric attacks increased by 40% compared to the previous quarter.[2]
Telecommunications providers bore the brunt of these assaults, accounting for 42% of hyper-volumetric attacks, followed by information technology and services providers at 15%.[1] Gaming companies and generative AI service providers were also heavily targeted.[2] Geographically, China, Hong Kong, Germany, and Brazil experienced the most attacks, with the US ranking fifth and the UK sixth.[1] Bangladesh topped the list of attack source locations, followed by Ecuador, Indonesia, Argentina, and Hong Kong.[1]
Mitigation: Cloudflare’s Autonomous Defense Response
Despite the unprecedented scale of the assault, Cloudflare’s autonomous DDoS defense systems detected and mitigated all attacks in real-time.[2] The company deployed its real-time botnet detection system, which successfully identified and blocked over 50% of HTTP DDoS attacks.[1]
Organizations can implement several protective measures:
- Deploy advanced DDoS mitigation solutions capable of handling hyper-volumetric attacks at network, transport, and application layers
- Implement rate limiting and traffic filtering to identify and block suspicious traffic patterns
- Monitor cloud infrastructure access to prevent abuse of virtual machines for launching attacks
- Utilize real-time threat intelligence to stay informed about emerging botnets and attack campaigns
- Establish incident response protocols to quickly identify and respond to DDoS activity
Cloudflare’s experience demonstrates that modern DDoS protection requires autonomous, adaptive systems capable of learning and responding to evolving threats. The company’s ability to automatically detect and mitigate the 31.4 Tbps attack without manual intervention highlights the critical importance of investing in next-generation security infrastructure.
Conclusion
The record-breaking 31.4 Tbps DDoS attack underscores a troubling reality: threat actors are leveraging the world’s most accessible and powerful network infrastructure to mount increasingly devastating assaults. With DDoS attacks more than doubling in 2025 and hyper-volumetric attacks growing 700%, organizations must recognize that legacy DDoS protection solutions are no longer sufficient. The Aisuru/Kimwolf botnet’s capabilities—and the ease with which cloud providers can be weaponized—suggest that this record may not stand for long. As the digital landscape continues to evolve, the cat-and-mouse game between defenders and attackers will only intensify, making continuous investment in advanced threat detection and mitigation essential for protecting critical infrastructure.