Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services

Anh V. Vu (University of Cambridge)

34th USENIX Security Symposium (USENIX Security '25) · Day 2 · Network Security 2: Routing and DoS

Overview

"TapTrap: Animation-Driven Tapjacking on Android" introduces a novel and stealthy attack vector that exploits Android's activity transition animations to circumvent the platform's permission model and existing tapjacking defenses. Developed by researchers Philipp Beer, Marco Squarcina, Sebastian Roth, and Martina Lindorfer, TapTrap demonstrates how a zero-permission malicious application can trick users into performing unintended, sensitive actions by manipulating the visual presentation of the user interface during activity transitions. This fundamental shift from traditional overlay-based tapjacking techniques allows TapTrap to remain effective even on the latest Android 15, presenting a significant security challenge.

Watch on YouTube · Read the paper · Download the PDF (PDF) · Slides

Paper abstract

Users interact with mobile devices under the assumption that the graphical user interface (GUI) accurately reflects their actions, a trust fundamental to the user experience. In this work, we present TapTrap , a novel attack that enables zero-permission apps to exploit UI animations to undermine this trust relationship. TapTrap can be used by a malicious app to stealthily bypass Android's permission system and gain access to sensitive data or execute destructive actions, such as wiping the device without user approval. Its impact extends beyond the Android ecosystem, enabling tapjacking and Web clickjacking. TapTrap is able to bypass existing tapjacking defenses, as those are targeted toward overlays. Our novel approach, instead, abuses activity transition animations and is effective even on Android 15. We analyzed 99,705 apps from the Play Store to assess whether TapTrap is actively exploited in the wild. Our analysis found no evidence of such exploitation. Additionally, we conducted a large-scale study on these apps and discovered that 76.3% of apps are vulnerable to TapTrap. Finally, we evaluated the real-world feasibility of TapTrap through a user study with 20 participants, showing that all of them failed to notice at least one attack variant. Our findings have resulted in two assigned CVEs.

Visual summary for Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services by Anh V. Vu
Visual summary for Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services by Anh V. Vu

Key moments

  1. 0:00 Introduction to DDoS-for-hire services
  2. 1:00 Overview of a typical booters dashboard
  3. 3:50 Details of the global law enforcement takedown
  4. 4:30 Data collection methods for impact assessment
  5. 5:50 Observation: Booters resurrected quickly after takedown
  6. 7:00 Impact on supply: Reduced booters' visit traffic
  7. 8:00 Impact on operators: Some left the market
  8. 9:20 Impact on demand: Significant drop in global attacks

Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services

Speakers: Anh V. Vu

Conference: USENIX Security

YouTube: https://www.youtube.com/watch?v=fDQ80hnChOw

Overview

This talk, presented by Anh V. Vu from the University of Cambridge, delves into the efficacy and aftermath of recent global law enforcement takedowns targeting DDoS-for-hire services, commonly known as booters or stressers. These services significantly lower the barrier to entry for launching distributed denial-of-service (DDoS) attacks, making sophisticated cyberattacks accessible to individuals with minimal technical skill and a budget as low as $10-$20. The research meticulously analyzes the impact of two major takedown waves, executed by the FBI, UK National Crime Agency, and Dutch police in December 2022 and May 2023, on both the supply side (booter operations) and the demand side (global DDoS attack volumes).

The study's primary objective was to assess whether these intensive law enforcement interventions achieved their intended long-term disruption. By examining various data sources, including web traffic to seized domains, Telegram chat channels used by operators, and multiple academic and industry DDoS attack datasets, the researchers provide a comprehensive picture of the cybercriminal ecosystem's resilience. The findings offer crucial insights for policymakers, law enforcement, and cybersecurity professionals, highlighting the persistent challenges in combating readily available cybercrime services and informing future defensive strategies.

The talk underscores the critical importance of understanding the dynamics of the DDoS-for-hire market. While operators often attempt to legitimize their services as tools for testing server resilience, their primary use involves illegal activities, enabling even technically unsophisticated individuals to disrupt online services, from small websites to online gaming environments. The ease with which these attacks can be launched, coupled with the fragmented nature of many smaller attacks, often allows them to fly under the radar of serious law enforcement attention, making large-scale takedowns a vital, albeit complex, countermeasure.

Background

▶ Watch: Introduction to DDoS-for-hire services (0:00)

Distributed Denial-of-Service (DDoS) attacks are a fundamental threat in the cybersecurity landscape. The basic premise involves overwhelming a target system, server, or network with a flood of unwanted traffic, rendering it inaccessible to legitimate users. Traditionally, executing a significant DDoS attack required considerable technical expertise, including the ability to compromise and control a large network of machines (a botnet) to generate the malicious traffic. However, the emergence of DDoS-for-hire services, or "booters" and "stressers," has democratized this capability, making it available to virtually anyone.

These services operate as a "DDoS-as-a-service" model, allowing users to pay a fee—often as little as $10-$20 per month—to launch attacks against specified targets. The speaker illustrated a typical booter dashboard, showing features like the number of attacks performed, running attacks, and total users. While these self-reported statistics can be inflated, prior research from 2018 indicated their general authenticity. Plans vary in cost and capability, offering different attack durations, simultaneous attack limits, and premium attack vectors. The ease of use is striking: users simply input an IP address or domain, select attack parameters (duration, requests per IP, method), and click "send attack." This model necessitates almost no technical skills, making it accessible even to high school students, as highlighted in the talk.

The proliferation of booters creates a significant problem: it facilitates a high volume of smaller, less severe attacks that individually may not attract significant law enforcement attention. These attacks are often sufficient to take down small websites lacking robust security protections or to congest networks, disrupting online games or services. The operators of these services often attempt to justify their existence by claiming they provide "stress testing" services for server resilience, but their primary application and methods are unequivocally illegal. This low barrier to entry and the ease of execution underscore why global law enforcement agencies have prioritized interventions against these services, aiming to disrupt the ecosystem at its source.

Key Findings

▶ Watch: Details of the global law enforcement takedown (3:50)

The research presented a multi-faceted analysis of the takedown's impact, revealing both initial successes and significant long-term challenges.

One of the most striking findings concerned the speed of booter resurrection. Following the first wave of takedowns in December 2022, over half (more than 25 of 49) of the seized domains returned online within a median of just one day, with some resurfacing in as little as 20 hours. In the second wave in May 2023, which targeted 13 domains (11 of which were new domains from the first wave's seized booters, and two entirely new), an astonishing 100% of the seized booters returned, with a median resurrection time of approximately two days. This rapid re-establishment of operations demonstrates the inherent resilience and adaptability of these criminal enterprises.

The study also investigated the impact on API calls, which booters often use to provide services to second-tier "franchise" booters. While API calls dropped sharply immediately after the takedowns, the researchers observed instances where backend systems continued to make repeated API calls for months, suggesting that some downstream operators might not have immediately noticed the takedown or were slow to react.

On the supply side, the takedowns initially showed a positive impact. The first wave led to an 80-90% decrease in direct visits to the seized domains, and a rapid decline of over 80% in unique visitors within two weeks. Traffic then fragmented across the resurrected domains, stabilizing at around 5,000 visits per day, significantly lower than pre-takedown levels. Overall, despite resurrection attempts, the booters could not attract as much traffic as before, resulting in an estimated 90% reduction in total traffic to these services. Analysis of Telegram chat channels further supported this, showing a significant drop in activity after the first wave. Some operators explicitly expressed concerns, offered downtime compensation, or even attempted to sell their domains and source code, or sought freelance jobs, indicating an intent to exit the market. The second wave, however, had a minimal impact on both traffic and Telegram activity, suggesting diminishing returns for subsequent operations.

Regarding the demand side, the research employed an interrupted time series analysis on global DDoS attack volumes from four different datasets (Hopscotch, Ampot honeypots, NESCO data, and self-reported booter statistics). The first wave of takedowns had a statistically significant impact, causing a drop in weekly attack counts from approximately 45,000 to 25,000. This effect was particularly pronounced for UDP-based attacks, which saw a highly significant drop to their lowest level in two years, while TCP-based attacks showed a less significant decline (from around 300,000 to 240,000). This suggests that booters primarily facilitate UDP-based attacks. However, a critical finding was the short-lived nature of this impact. Across all datasets, the effect lasted for only about six weeks, after which attack volumes not only recovered but in some cases surpassed pre-takedown levels. The second wave, consistent with its minimal supply-side impact, showed unclear or negligible effects on global attack volumes.

In summary, while the takedowns achieved a substantial immediate disruption to the supply of DDoS-for-hire services and a statistically significant, albeit temporary, reduction in global DDoS attack volumes, the overall impact proved to be quite short-lived, lasting roughly six weeks. The rapid resurrection of services and the persistent demand indicate that suppressing the supply alone may not suffice for long-term effectiveness.

Technical Deep Dive

▶ Watch: Observation: Booters resurrected quickly after takedown (5:50)

The research meticulously analyzed the impact of two significant global law enforcement operations against DDoS-for-hire services. The first wave occurred in December 2022, involving the seizure of 49 domains associated with the largest booters. The second wave followed in May 2023, targeting an additional 13 domains. To maximize the intelligence gathering from these takedowns, the law enforcement agencies, in collaboration with the researchers' center, hosted splash pages on the seized domains. These pages collected access information, providing critical data on who was accessing the booters and whether users were attempting to migrate between different services after a takedown. This effort successfully captured 21 million traffic visits to these splash pages.

To understand the resilience and adaptability of the booter ecosystem, the researchers employed a multi-pronged data collection strategy. Thousands of messages were collected from Telegram chat channels operated by booters. These channels served as communication hubs for operators to advertise successful attacks, deliver updates, and provide customer support. By analyzing chat content, the team identified new domains that emerged post-seizure, observed operators' reactions—such as offering downtime compensation, advertising domains/source code for sale, or seeking freelance work—and gained insights into their intent to continue or exit the market.

In addition to direct observations, web traffic data was collected for both seized and subsequently resurrected domains to quantify changes in service availability and user engagement. To measure the broader landscape of global DDoS attacks, the study integrated several external datasets:

  • Hopscotch honeypot: An academic dataset providing a view of attack traffic.
  • Ampot honeypot: Another academic honeypot dataset, offering a complementary perspective on attack trends.
  • NESCO data set: An industry-provided dataset, contributing real-world attack metrics.
  • Self-reported statistics: The researchers conducted weekly visits to hundreds of active booters over two years, collecting their self-reported attack statistics for comparative analysis.

The impact on global attack volume was rigorously assessed using an interrupted time series analysis. This statistical modeling technique is designed to evaluate the effect of an intervention (in this case, the takedown waves) on a time-series dataset. The model incorporated various components, including underlying trends, seasonal variations (e.g., increased attacks around holidays like Christmas or Easter), and the specific intervention effects of the two takedown waves. By comparing the observed attack volumes before and after the interventions with a counterfactual scenario (what would have happened without the intervention), the researchers could determine the statistical significance and duration of the takedowns' impact.

The analysis specifically differentiated between UDP-based and TCP-based attacks. UDP-based attacks, often associated with reflection/amplification techniques commonly employed by booters, showed a highly statistically significant drop after the first wave, reaching their lowest levels in two years. In contrast, TCP-based attacks, while showing a decline, did not experience as significant a drop over the entire series. This distinction is crucial, as it suggests that the takedowns were particularly effective against the specific attack vectors favored by these services. However, the consistent finding across all four datasets was that the statistically significant effects of the first wave lasted for only approximately six weeks, highlighting the market's rapid recovery and the persistent underlying demand for these services.

Demo / Proof of Concept

▶ Watch: Impact on supply: Reduced booters' visit traffic (7:00)

While the conference talk did not feature a live, interactive demonstration of a new exploit or tool, the speaker did provide a compelling proof-of-concept for the accessibility and efficacy of DDoS-for-hire services. Anh V. Vu explicitly stated, "I tried this on my own dummy website and it actually works." This anecdotal demonstration, conducted by the researcher using a readily available booter service, served to underscore the core problem addressed by the talk: the ease with which individuals, even those without technical expertise, can launch effective DDoS attacks. It effectively illustrated that the low cost and simple interface of these services translate directly into real-world disruptive capability against unprotected targets.

Furthermore, the talk presented the splash page that law enforcement and the research team collaboratively hosted on seized booter domains. This page, which users would encounter when attempting to access a taken-down service, served as a "demonstration" of the takedown's operational capabilities. By collecting access information from 21 million visits, this splash page acted as a sophisticated intelligence-gathering mechanism. It demonstrated how law enforcement leveraged the takedown event itself to gain insights into the user base and their migration patterns between different services, effectively turning a disruption into a data collection opportunity. Although not a traditional "hack demo," these elements provided concrete evidence of both the threat and the response.

Defensive Implications

▶ Watch: Impact on demand: Significant drop in global attacks (9:20)

The findings from this research offer critical insights for network defenders and cybersecurity professionals. While global law enforcement takedowns of DDoS-for-hire services can achieve significant immediate disruption, their long-term effectiveness is limited by the rapid resurrection of services and persistent demand. Therefore, organizations should not view these interventions as a primary or standalone defense mechanism.

Key defensive implications include:

  1. Proactive DDoS Mitigation is Paramount: Given the short-lived impact of takedowns (approximately six weeks), organizations must implement robust, always-on DDoS mitigation strategies. This includes deploying DDoS scrubbing services (on-premise or cloud-based), leveraging Content Delivery Networks (CDNs) for traffic distribution and caching, and implementing rate limiting at various network layers.
  2. Focus on UDP-based Attack Vectors: The research highlighted a primary effect on UDP-based attacks, which are common for booters due to their effectiveness in amplification and reflection attacks. Defenders should pay particular attention to protecting against common UDP-based DDoS vectors, such as DNS, NTP, SSDP, and Memcached amplification, by implementing strong ingress/egress filtering, source IP validation (BCP38), and configuring network devices to drop malformed UDP packets.
  3. Capacity Planning and Scalability: Organizations should regularly assess their network and application infrastructure's capacity to withstand large traffic volumes. This includes ensuring sufficient bandwidth, server resources, and the ability to scale resources dynamically in response to an attack.
  4. Layered Security Approach: DDoS attacks can target various layers of the OSI model. A comprehensive defense requires a layered approach, including network-level protections (Layer 3/4), application-level protections (Layer 7, e.g., Web Application Firewalls or WAFs), and DNS-based defenses.
  5. Incident Response Planning: Develop and regularly test a detailed DDoS incident response plan. This plan should outline procedures for detection, validation, mitigation activation, communication protocols, and post-incident analysis. Understanding how to quickly engage with ISPs and DDoS mitigation providers is crucial.
  6. Monitoring and Threat Intelligence: Continuous monitoring of network traffic for anomalies and staying informed about emerging DDoS attack trends and booter capabilities through threat intelligence feeds can help organizations anticipate and respond to evolving threats.
  7. Leverage Law Enforcement Data (where available): The study noted that data sets are available on request through the Cambridge Cyber Crime Center. Accessing such academic and industry data can help organizations understand the current threat landscape and tailor their defenses accordingly. While takedowns may not provide long-term immunity, they can offer temporary relief during periods of heightened risk, such as holiday seasons (Christmas, Easter), allowing organizations a window to reinforce their defenses or recover.

Key Takeaways

  • DDoS-for-hire services (booters/stressers) make sophisticated DDoS attacks easily accessible and affordable ($10-$20), requiring almost no technical skill.
  • Global law enforcement takedowns, like those in December 2022 and May 2023, achieve a significant initial disruption to the supply of these services and a statistically significant reduction in global DDoS attack volumes.
  • The impact of these takedowns is short-lived, typically lasting only about six weeks, after which attack volumes often recover to or even surpass pre-takedown levels.
  • Booter resurrection is rapid and resilient: Over half of seized domains returned within a day in the first wave, and 100% returned within two days in the second wave.
  • The takedowns showed a primary effect on UDP-based attacks, which are commonly associated with booter services, indicating their specific effectiveness against these vectors.
  • Suppressing supply alone is insufficient for long-term disruption; the underlying demand for DDoS attacks persists, leading to rapid market recovery and adaptation by operators.

About the Speaker(s)

The talk was presented by Anh V. Vu, a researcher associated with the University of Cambridge. Anh V. Vu's work in this domain focuses on understanding the dynamics of cybercrime ecosystems and the effectiveness of interventions against them. This specific research was a collaborative effort with colleagues Ben, Danielle, John, Richard, and Alice, and involved extensive data collection and analysis facilitated by the Cambridge Cyber Crime Center. The center makes some of its datasets available upon request for further academic and industry research.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Rigorous empirical work on a question the security community hand-waves constantly: do takedowns actually work? The interrupted time series methodology, multi-dataset triangulation, and the six-week half-life finding give this real teeth — this is the kind of answer law enforcement and policymakers need to hear, even if they won't like it.

Heather Calloway (CISO) — SOLID

Rigorous academic work with a clear, honest answer: law enforcement takedowns buy roughly six weeks of disruption before the market reconstitutes itself. Credible methodology, policy-relevant conclusion — but the talk stops at diagnosis and never reaches the institutional question its own findings demand.

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)