Distributed denial-of-service (DDoS) attacks are increasingly targeting ultra domain name system (UltraDNS) as a means to breach critical infrastructure.
DigiCert’s latest "2025 Radar Brief" revealed that attacks targeting UltraDNS – cloud-hosted DNS services designed to securely guide user query responses for enterprises – soared in late 2025, with some 176 events spotted in December alone.
Figures suggest UltraDNS processed some 4.75 trillion authoritative queries that same month, a 10% jump from October, with attackers seemingly eying it as an increasingly attractive attack surface while also looking to take advantage of the peak traffic times brought about by the holiday season.
DDoS attacks in general increased in frequency, scale, and duration during the final three months of last year, as an already worrying trend of increased attacks continues.
DigiCert’s findings affirmed wider industry knowledge that attacks are getting bigger, with the Aisuru botnet running riot throughout the last quarter, including an effort that peaked at 31.4 Tb/s, earning it the “apex of botnets” moniker from Cloudflare.
Other hyper-volumetric DDoS attacks – where masses of hijacked devices are used to saturate a network at such size and speed that operators have next to no time to react – include a 22.2 Tb/s incident stopped last December, and an 11.5 Tb/s attack put down by Cloudflare.
DigiCert's report suggested that packet-rate intensity of attacks also surged during the last quarter, with attacks peaking at around 424 Mb/s.
In addition to attacks getting larger, DigiCert’s report suggests DDoS efforts are running for longer. According to the findings, the longest attack spotted in December extended beyond eight days.
With the increasing size and now length, DigiCert warns that attackers are essentially looking to wear down infrastructure over time, in place of short, probing attacks to prolong strain.
That approach, however, is flipped when it comes to threats at the application layer, with DigiCert suggesting loud, one-time attacks are instead being replaced with more ongoing probing to uncover weaknesses over time through quieter methods. These include cookie manipulation – where attackers either steal a user’s session cookie to gain unauthorized access, or even inject malicious code into cookies to steal sensitive data.
“What Q4 reinforces is that resilience is no longer about absorbing isolated spikes in traffic and attacks,” DigiCert AppSec CTO Michael Smith explained. “With the ever-increasing scale of internet bandwidth and the creation of the Aisuru and Kimwolf botnets, organizations must be prepared to operate under prolonged demand and sustained attack pressure across DNS, network, and application layers simultaneously.”
Comments