Cybersecurity faces the continued onslaught of distributed denial-of-service (DDoS) attacks. Websites, applications, and online services flooded with junk traffic are unable to serve legitimate users. Businesses lose revenue, budgets are strained, and customers lose faith. DDoS may not get the attention of ransomware headlines, but attackers are changing their tactics to launch larger, more sophisticated attacks. In this day and age, it’s easier to orchestrate for a range of purposes, including extortion, disruption, hacktivism, or hurting competitors’ bottom lines.
Many are also powered by massive botnets made up of millions of compromised IoT devices. In this podcast episode of Security Strategist, host Richard Stiennon talks with Qrator Labs CTO Andrey Leskin about how these attacks are evolving and what organisations need to do to keep pace. They explore the growing scale and complexity of attacks, the role of massive botnets, practical approaches to DDoS mitigation, and how AI could accelerate existing attack capabilities.
The Biggest Trend is Scale
Leskin started at Qrator Labs as a developer 14 years ago and worked his way up to chief technology officer. “I started off as the guy in IT who woke up at 3 a.m. because something stopped working,” Leskin tells Stiennon. “Now I’m the lucky guy who gets to wake up and try to fix things for our clients.”
Today Qrator Labs manages cloud scrubbing infrastructure, bot management tools, and network monitoring services for hundreds of banks, betting platforms, e-commerce firms, media, education, tourism, and telcos throughout North and South America, Europe, the Middle East and Asia. That broad exposure gives him insight into the latest attack patterns. “Scale is the biggest trend,” Leskin says. An attack earlier this year topped two terabits per second and nearly one billion packets per second. It sustained that traffic rate for more than 40 minutes. During Q2, the company saw a doubling in terabit attacks (meaning attacks of one trillion bits per second or greater) year-over-year.
“That used to be a super-rare once-a-quarter type of thing,” Leskin said. “Twelve is not unique. Bandwidth that used to be exceptional is now just regular Tuesday.” Botnets powering these attacks are getting bigger, too. One botnet monitored by Qrator since March of last year grew from around 1.5 million bots to over 13 million within about a year. The geographic diversity of infected hosts also continues to expand, making filtering traffic based on region less effective as an automated mitigation technique.
Attacks are also easier to launch than ever before. Today attackers can find DDoS-for-hire services that simplify everything except deciding how much money they want to spend. Make the payment in cryptocurrency, paste in a target IP address or URL, and press launch. Many don’t need advanced technical knowledge. Decentralised command and control systems, including botnets using blockchain technology to coordinate activity, are complicating mitigation efforts further.
Existing Mitigations Fall Short
A common DDoS myth, Leskin says, is the idea that hosting with a cloud provider or CDN somehow provides adequate protection from DDoS attacks. While a website or app might remain available, those services are designed to maximise uptime and performance, not fend off attacks specifically. Organisations are still on the hook for all of the network resources an attack consumes. “And then when the monthly bill arrives you realise you were DDoS’ed on your wallet,” Leskin said.
When Bots Overwhelm Defenses
Q1 telemetry shows bots, DDoS and BGP faults converging into a persistent threat baseline, reshaping security planning and resilience priorities.
Attackers are also leveraging multiple attack vectors more frequently. Instead of a single volumetric flood or application-layer attack, defenders might see both plus attempts to overwhelm other dependencies like a firm’s merchant processor. Leskin highlights how betting platforms saw an onslaught of attacks during the recent World Cup. Financial-services firms and fintech companies made up 44 per cent of DDoS attacks in Q1. That figure fell to 22 per cent in Q2 as attackers shifted their focus to gambling platforms, where attacks reached 1.5 terabits per second.
Tips for Defending Against Tomorrow’s Attacks
Preparing for these evolving threats starts with being operationally prepared, rather than buying into any one silver-bullet technology, Leskin said:
- Know and understand your normal traffic profile down to the protocol level and by time of day or season. Traffic during a World Cup final will look very different to normal operations for a betting platform.
- Expect blended attacks that use more than one vector designed to evade traditional DDoS mitigation systems.
- Botnets are nothing new, but blocking them is still important. In the first quarter of 2026, Qrator blocked an average of 2.5 billion malicious bot requests each month. While not considered DDoS, these attacks can still have a significant impact on performance.
- Have an incident response plan that you’ve practised so you can respond as quickly as possible when an attack happens.
From a tech perspective, there are two main categories of DDoS mitigation, each with advantages and disadvantages:
| Approach | Strengths | Limitations |
| DNS-based protection | Easy to implement; works well at mitigating attacks against websites and web applications | Doesn’t work for everything routed outside of DNS, like voice services or game servers |
| BGP-based mitigation | Handles any type of network traffic at the network layer. | You need to own your own network; can take up to one full day to implement. |
AI and DDoS Attacks
Inside Telecom-Grade DDoS Defense
A look at how distributed filtering safeguarded DNS, APIs and portals from 1,000x traffic spikes without degrading performance.
Leskin says that he doesn't expect AI to introduce new types of attacks. Instead, he sees it accelerating what already exists, helping attackers scan for vulnerable devices faster, automate reconnaissance, and grow botnets more efficiently. In other words, AI mostly lowers the cost and skill threshold for doing what attackers already do. Combined with the rise of DDoS-for-hire services, pushes more of the "easy attack" trend described earlier. His closing point was less about tools than posture: "Security isn't a state you achieve one time. It's a process you maintain, because whatever you're defending against is actively evolving against you."
The figures cited reflect Qrator Labs’ own network telemetry and provide a view into the attack trends observed across its protected infrastructure. While they do not represent the entire global DDoS landscape, they highlight a clear direction. For most organisations, the practical implication isn't "buy more bandwidth." It's building the muscle memory, traffic baselines, tested response plans, and mitigation that matches how you actually operate before an attack forces the issue. If you would like to learn more, visit qrator.net or follow Andrey Leskin on LinkedIn.
Takeaways
- The scale and evolution of DDoS attacks from 2020 to 2026.
- The role of botnets and their growth in size and geographic diversity.
- Common motivations behind DDoS attacks.
- Limitations of CDN and cloud provider protections against DDoS.
- Best practices for organisations to assess and improve their DDoS resilience.
- Technical mitigation techniques including DNS and BGP-based protections.
- The importance of continuous security posture review.
- Future trends including AI-driven attack methods and multi-vector incidents
Comments ( 0 )