Site navigation

Dark‑Web LLMs Are Supercharging DDoS Attacks

Tom Quinn

,

DDoS attacks
“Traditional security defences are no longer working, and with attackers hitting new attack size and complexity ceilings,” said Richard Hummel, NetScout.

More than eight million DDoS attacks were recorded worldwide over the second half of last year, some hitting record-breaking peaks, according to the latest research from NetScout, evidence of a new era of hyper-scale, coordinated threat activity.

The cyber firm’s latest DDoS Threat Intelligence Report details waves of coordinated botnets and hacktivists groups behind millions of cyber-attacks, with their operations supercharged by the emergence of sophisticated AI tools and dark-web LLMs.

NetScout logged over 20,000 botnet‑powered attacks in the summer of 2025 alone, driven by Aisuru and TurboMirai variants, with H2 assaults surging to peaks of 30 Tbps and 4 Gpps, an overwhelming force hackers used to target government, finance, and transportation services, which saw the highest concentration of DDoS attacks.

Despite international law enforcement dismantling several DDoS-for-hire platforms last year, their efforts did little to slow the pace of attacks. Hacktivist groups and botnets kept up the pressure, with NoName057(16) alone boasting more than 200 attacks in July, with the group bouncing back quickly after losing parts of its infrastructure to law‑enforcement seizures.

Meanwhile, critical internet infrastructure, such as Network Time Protocol and DNS root servers, faced continuous pressure, generating more than 45,000 attack alerts over the period, which NetScout said points to the need for highly resilient, globally distributed architectures to maintain service continuity.

The report also presents specific implications for security professionals at enterprise firms extending far beyond what NetScout calls “volumetric concerns” aimed at net infrastructure.

For example, the report found that hacked smart devices and on-premise routers can unleash more than 1 Tbps of malicious traffic when hijacked, while threat actors are also ramping up their use of multi-vector attacks, with 42% of DDoS incidents employing two to five distinct attack vectors, complicating detection and mitigation.


Recommended reading


AI remains the most immediate and fastest‑growing threat, however, with NetScout reporting a 219% surge in references to malicious AI tools among tracked threat groups. Among the most popular are dark-web models like WormGPT and Fraud GPT, competitively priced as low as $60 per month. 

Conversational AI systems, such as these malicious chatbots, have emerged as a particularly worrying vector for abuse, allowing newbie DDoS operators to define their objectives in plain language while the system manages all technical details, opening up the field to far less sophisticated players.

“Threat actors identify organisations that haven’t invested in the right defences to stay ahead of sophisticated and coordinated DDoS attacks to take down critical infrastructure,” said Richard Hummel, director of threat intelligence at NetScout. 

“Traditional security defences are no longer working, and with attackers hitting new attack size and complexity ceilings, implementing automated and proactive defences has become a business-level risk mandate – not just a technical concern for security professionals.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data