Qrator Labs reported that the largest botnet it tracks grew from roughly 1.33 million devices in March 2025 to 13.5 million devices in Q1 2026, driving a new wave of massive distributed denial-of-service attacks against financially focused organizations. The firm said FinTech, banks, and payment systems were the most targeted sectors, as attackers increasingly combined L3/L4 and L7 techniques in larger, more complex multi-vector campaigns. It also recorded a rise in bad-bot activity, with an average of 2.5 billion blocked requests per month.
One of the most significant incidents hit the betting industry in mid-March, peaking at 2.065 Tbps and nearly 1 billion packets per second over about 40 minutes, with attackers shifting tactics 11 times during the assault. Qrator linked the broader trend to evolving botnet tradecraft, including a new loader called Aeternum C2 that uses the Polygon blockchain for decentralized command-and-control, and to the continued evolution of large-scale botnet operations previously associated with record-setting campaigns such as Mēris.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Qrator Labs disclosed technical details on a new loader called Aeternum C2 that uses the Polygon blockchain for decentralized command-and-control. The finding highlighted an evolution in botnet resilience and infrastructure design.
Qrator Labs said the largest tracked DDoS botnet expanded to 13.5 million devices in the first quarter of 2026, enabling multi-terabit attacks. The report also noted increased multi-vector activity and financially oriented sectors such as FinTech, banks, and payment systems as leading targets.
In mid-March 2026, Qrator Labs observed a major DDoS attack against a betting-sector organization that peaked at 2.065 Tbps and nearly 1 billion packets per second for about 40 minutes. During the attack, the operators reportedly changed tactics 11 times, indicating a complex multi-vector operation.
Qrator Labs reported that the largest tracked DDoS botnet had a size of about 1.33 million devices in March 2025. This serves as the baseline before the botnet's later rapid expansion.
Qrator Labs published analysis of the Mēris botnet, documenting its rise and record-setting DDoS capabilities. This established the botnet as a major large-scale DDoS threat.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.