USENIX Security2025Top-tier venue
Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services
Anh V. Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, Alice Hutchings
Abstract
Law enforcement and private-sector partners have in recent years conducted various interventions to disrupt the DDoS-for-hire market. Drawing on multiple quantitative datasets, including web traffic and ground-truth visits to seized websites, millions of DDoS attack records from academic, industry, and self-reported statistics, along with chats on underground forums and Telegram channels, we assess the effects of an ongoing global intervention against DDoS-for-hire services since December 2022. This is the most extensive booter takedown to date conducted, combining targeting infrastructure with digital influence tactics in a concerted effort by law enforcement across several countries with two waves of website takedowns and the use of deceptive domains. We found over half of the seized sites in the first wave returned within a median of one day, while all booters seized in the second wave returned within a median of two days. Re-emerged booter domains, despite closely resembling old ones, struggled to attract visitors (80-90% traffic reduction). While the first wave cut the global DDoS attack volume by 20-40% with a statistically significant effect specifically on UDP-based DDoS attacks (commonly attributed to booters), the impact of the second wave appeared minimal. Underground discussions indicated a cumulative impact, leading to changes in user perceptions of safety and causing some operators to leave the market. Despite the extensive intervention efforts, all DDoS datasets consistently suggest that the illicit market is fairly resilient, with an overall short-lived effect on the global DDoS attack volume lasting for at most only around six weeks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Meme Coin Factories: Uncovering Large-Scale Manipulations on pump.funNicolas Szwajcok, Taro Tsuchiya, Enze Liu, Kyle Soska et al.CCS 2026
- From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire BotnetMaarten Weyns, Dario Ferrero, Stefan Op de Beek, Daniel Wagner et al.USENIX Security 2026
- On the Security Risks of Memory Adaptation and Augmentation in Data-plane DoS MitigationHocheol Nam, Daehyun Lim, Huancheng Zhou, Guofei Gu et al.NDSS 2026
Builds on6
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon et al.S&P 2016 · 76 citations
- Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downsEihal Alowaisheq, Peng Wang, Sumayah A. Alrwais, Xiaojing Liao et al.NDSS 2019 · 48 citations
- Scan, Test, Execute: Adversarial Tactics in Amplification DDoS AttacksHarm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian DoerrCCS 2021 · 35 citations
- No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and HarassmentAnh V. Vu, Alice Hutchings, Ross J. AndersonS&P 2024 · 13 citations
- Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine ConflictAnh V. Vu, Daniel R. Thomas, Ben Collier, Alice Hutchings et al.WWW 2024 · 8 citations
Related papers
- Platforms in Everything: Analyzing Ground-Truth Data on the Anatomy and Economics of Bullet-Proof HostingArman Noroozian, Jan Koenders, Eelco van Veldhuizen, Carlos Hernandez Gañán et al.USENIX Security 2019 · 40 citations
- A Practical Approach for Taking Down Avalanche Botnets Under Real-World ConstraintsVictor Le Pochat, Tim Van hamme, Sourena Maroofi, Tom van Goethem et al.NDSS 2020
- 7 Days Later: Analyzing Phishing-Site Lifespan After DetectedKiho Lee, Kyungchan Lim, Hyoungshick Kim, Yonghwi Kwon et al.WWW 2025 · 5 citations
- Under the Shadow of Sunshine: Understanding and Detecting Bulletproof Hosting on Legitimate Service Provider NetworksSumayah A. Alrwais, Xiaojing Liao, Xianghang Mi, Peng Wang et al.S&P 2017 · 51 citations
- Where are you taking me?Understanding Abusive Traffic Distribution SystemsJanos Szurdi, Meng Luo, Brian Kondracki, Nick Nikiforakis et al.WWW 2021 · 13 citations
