DigiCert has unveiled its Q4 2025 RADAR Threat Intelligence Brief, offering detailed insights into the intersection of worldwide internet demand and cybersecurity challenges during the final quarter of the year. Based on trillions of network activities observed via DigiCert’s expansive security platform—comprising UltraDNS, UltraDDoS Protect, and UltraWAF—this report presents a detailed examination of the contemporary threat environment.
The fourth-quarter analysis indicates ongoing, considerable pressure on internet infrastructure as the year concludes. There is a rise in online activities due to business cycles, consumer transactions, travel-related surges, and new device activations. These events coincide with increased malicious actions, underscoring the importance of robust, multi-layered security solutions.
Elevated online content demand
Data indicates consistently high internet traffic, with notable spikes around significant events. DigiCert’s DNS metrics reveal that what were previously short demand surges have transformed into prolonged periods of high load, extending across weeks. During these busy seasons, the notion of "off-peak" periods no longer applies.
Additionally, there was a persistent rise in certain DNS signals, including NXDOMAIN requests and automation tool queries, suggesting continual activity in:
- Internet scanning
- System misconfigurations causing repeated bad requests
- Automated probing by bots and reconnaissance tools
Significance:
- Peak demand has become the standard, eliminating reliance on brief recovery times.
- Continuous DNS pressure exists, even when it appears otherwise.
- Manual or reactive security strategies are ineffective against sustained demand.
- Increased risks of outages and exploitation due to ongoing scanning and misconfigurations.
Evolution of DDoS activity
Throughout Q4, DDoS attacks grew in number, magnitude, and longevity. Instead of short disruptions, attacks now aim to apply prolonged pressure, indicating a strategic shift towards weakening infrastructure over time.
Implications:
- Extended attacks necessitate prolonged defensive responses, rather than quick fixes.
- There is a heightened risk of performance degradation, beyond complete outages.
- Conventional defenses designed for brief spikes may be inadequate against enduring pressures.
- Sustained attacks increase operational costs and affect customer experiences.
Focused application-layer threats
Web application threats remain predominantly automated, with attackers persistently testing application responses to various requests. Rather than loud, singular assaults, attackers are engaging in persistent probing using techniques like cookie manipulation to uncover weaknesses quietly over time. Despite fluctuating attack volumes, the approach remains unchanged: covert, continuous testing rather than overt disruption.
Consequences:
- Applications face ongoing testing even when traffic appears normal.
- Subtle attacks are difficult to detect and can persist longer.
- Consistent probing can escalate minor misconfigurations into significant security issues.
- Defenses must function continuously, not merely react to apparent spikes.
Enduring through constant demand and pressure
“What Q4 reinforces is that resilience is no longer about absorbing isolated spikes in traffic and attacks,” stated Michael Smith, AppSec CTO at DigiCert.
“With the ever-increasing scale of internet bandwidth and the creation of the Aisuru and Kimwolf botnets, organisations must be prepared to operate under prolonged demand and sustained attack pressure across DNS, network, and application layers simultaneously.”
DigiCert, a foremost global provider of intelligent trust, released its Q4 2025 RADAR Threat Intelligence Brief, delivering data-driven insights into how global internet demand and cyber threats converged during the fourth quarter.
Drawing from trillions of network events across DigiCert’s global security platform, which includes UltraDNS, UltraDDoS Protect, and UltraWAF, RADAR provides one of the most comprehensive views of today’s evolving threat landscape.
The Q4 RADAR Brief shows that the year-end period continues to place unique and sustained pressure on internet infrastructure. Seasonal increases in online activity, driven by business cycles, consumer commerce, travel, and device activation coincided with a measurable escalation in malicious activity, reinforcing the need for resilient, layered security strategies.
Key findings from the Q4 2025 RADAR brief
1.Demand for online content remained elevated throughout the quarter.
Internet traffic exhibited consistently high growth during the entire quarter with a few short spikes around major events. DigiCert’s DNS usage data shows what used to be brief periods of heavy demand have turned into longer stretches of sustained load, lasting weeks instead of days. There is no clear “off-peak” anymore during busy seasons.
At the same time, certain DNS signals like NXDOMAIN requests (failed lookups) and queries from automation tools stayed higher than normal. This suggests a constant level of:
- Internet scanning
- Misconfigured systems repeatedly making bad requests
- Automated probing or reconnaissance by bots and tools
Why it matters:
- Peak demand is becoming the norm, not the exception: Systems can’t rely on short recovery windows anymore.
- Background “noise” is higher all the time: Even when nothing obvious is happening, DNS infrastructure is under continuous pressure.
- Manual or reactive approaches don’t scale: Because load is sustained vs. spiking and dropping.
- Security and availability risks increase quietly: Persistent scanning and misconfiguration create more opportunities for outages or exploitation.
2. DDoS activity intensified and evolved.
DDoS attacks increased in frequency, scale, and duration as Q4 progressed. Rather than brief disruptions, attackers increasingly ran longer and larger attacks designed to place sustained pressure on systems and defenses.
This reflects a shift from short, probing attacks to prolonged strain, with attackers aiming to wear down infrastructure over time.
Why it matters:
- DDoS is no longer a quick disruption; attacks are lasting longer and demanding sustained response.
- Prolonged attacks increase the risk of degraded performance, not just full outages.
- Defenses built for short spikes may fall short against extended pressure.
- Longer attacks quietly raise operational costs and customer impact.
3. Application-layer threats remained highly automated but more focused.
Web application attacks continued to be driven largely by automated tools with attackers repeatedly testing how applications respond to different requests. Rather than launching loud, one-time attacks, activity focused on ongoing probing, using techniques such as cookie manipulation, to quietly look for weaknesses over time.
While overall volumes fluctuated, the behavior itself remained consistent: persistent, automated testing instead of obvious disruption.
Why it matters:
- Applications are under constant background testing, even when traffic appears normal.
- These quieter attacks are harder to spot and can persist longer.
- Repeated probing increases the risk that small misconfigurations turn into real security issues.
- Defenses must operate continuously, not just react to spikes.
Operate under demand and pressure
“What Q4 reinforces is that resilience is no longer about absorbing isolated spikes in traffic and attacks,” said Michael Smith, AppSec CTO at DigiCert.
“With the ever-increasing scale of internet bandwidth and the creation of the Aisuru and Kimwolf botnets, organisations must be prepared to operate under prolonged demand and sustained attack pressure across DNS, network, and application layers simultaneously.”