News

  • Report

Share

Facebook Twitter linkedin
2025.05.02

Approximately 6.92 million cyber attacks observed in one day, or approximately 80 attacks per second. The most targeted day in the first quarter of 2025 was March 14th. Release of the "Web Application Cyber Attack Detection Report" for January to March 2025.

Cyber Security Cloud, Inc., Inc. (Headquarters: Shinagawa-ku, Tokyo; Representative Director, President and CEO: Koike Toshihiro; hereinafter referred to as "Cyber Security Cloud"), a global security manufacturer, is pleased to announce the "Web Application Cyber Attack Detection Report (hereinafter referred to as "this report"), covering the period from January 1 to March 31, 2025. This report aggregates, analyzes, and calculates cyber attack logs observed by "Shadankun," Cloud-based WAF provided by Cyber Security Cloud that visualizes and blocks cyber attacks on web applications, and "WafCharm," an automated operation service for public cloud WAFs.

 

■ Total number of attacks and trends: 360 million cyber attacks detected in three months

The total number of cyber attacks against web applications detected by our company from January 1 to March 31, 2025 was 365,956,552. In addition, the number of attacks per host (※1) was 47,884.

 

During the survey period, the day with the most attacks was March 14, 2025, when the number of attacks detected reached 6,922,969. This equates to approximately 80 attacks per second.
Furthermore, it has been revealed that the average number of attacks per day from January to March of the previous year was approximately 2,298,029, and the number of attacks on March 14th was an abnormal spike equivalent to approximately three times this number.
Cyberattack activity increased from February to March 2025. February was a period marked by large-scale attacks using botnets, including DDoS attacks using the IoT botnet "Eleven11bot" reported both domestically and internationally.

Then, on March 10, a new serious remote code execution (RCE) vulnerability (CVE-2025-24813) in the web server "Apache Tomcat" was announced. This vulnerability was dangerous and could allow arbitrary code execution in a two-step manner, by writing an unauthorized session file with an HTTP PUT request and then accessing it with a crafted session ID via GET. Immediately after the vulnerability was announced, a PoC (proof of concept) was released, rapidly increasing the risk of exploitation.
In fact, an initial attack exploiting this vulnerability was confirmed in Poland on March 12, after which scans and attacks targeting the vulnerability spread rapidly around the world. Websites in Japan were also subject to this attack traffic, and as a result of a large number of HTTP requests (PUT/GET requests) being sent to poorly defended servers, an increase in accesses of approximately three times the normal amount was observed.

Furthermore, on March 14th, a supply chain attack occurred in which "changed-files," a popular GitHub Action, was temporarily taken over after falling victim to a cyberattack. This date coincided with the timing of an increase in fraudulent orders during the Valentine's Day and White Day festival seasons, and it is possible that a number of attacks were concentrated on this day as multiple factors intersected.
As described above, the succession of multiple threats that occurred from February to March, including botnet attacks, campaigns exploiting Apache Tomcat vulnerabilities, and incidents related to GitHub Actions, is likely what led to the sudden increase in cyber attacks overall.

(※1) Estimated calculation based on the total number of hosts protected by "Shadankun" (Web type: number of FQDNs, Server type: number of IPs) and the number of hosts protected by "WafCharm" (WebACLs).

 

 

■ Country of origin of the attack

In the ranking of attack source countries for Q1 2025, the United States, Japan, and Russia ranked at the top as usual, while South Africa, which was 25th in the same period last year, suddenly rose to 9th place.

Romania also rose from 11th to 4th place, suggesting that attacks from different regions are on the rise.

 

 

■Main attack types

Looking at the main types of attacks during this survey period, although the overall total number has increased, the main trend has not changed significantly from 2024. The most common type of attack is "Web scan," which accounts for 52% and is a "premonition of an attack" such as searching and investigating the target of an attack or searching for vulnerabilities with simple random attacks.

The fact that these "Web scans" have been observed so frequently indicates that the "preliminary steps" leading to a full-scale intrusion are already underway at many organizations. Web scans are a method of randomly investigating a wide range of systems and web applications to search for known vulnerabilities, rather than targeting specific companies. These scans may also have been used to search for DDoS targets by botnets. If vulnerabilities are detected during the scan and left unfixed, the risk of them being exploited by attackers increases dramatically.

 

■ Attacks against "PHPUnit" continue to increase from the previous year

It has been found that attacks on PHPUnit, a testing framework for PHP applications, which had not been very prominent until 2023, have continued to increase from the previous year.
PHPUnit is a framework for performing unit testing for the PHP programming language. A vulnerability in PHPUnit could allow an attacker to execute arbitrary PHP code remotely. This is a dangerous vulnerability that allows an attacker to perform a wide range of activities on the server via the PHP code.
Even after an increase of over 8.5 million attacks was observed in the second quarter of 2024, the number of attacks remained at a high level from January to March 2025.

 

 

■Comment from Cyber Security Cloud, Inc. Representative Director, CTO Yoji Watanabe

Observation data for the first quarter of 2025 revealed that threats surrounding web applications are becoming more sophisticated and complex in both frequency and method.
In particular, the abnormal spike in attacks recorded on March 14th - approximately 6.92 million attacks per day, or approximately 80 attacks per second - was roughly three times higher than usual, and is believed to have been the result of vulnerability searches and attack activities concentrated in a short period of time.

Additionally, in the ranking of attack source countries, South Africa, which had not made any notable movements until now, has suddenly risen from 25th to 9th, suggesting that attack infrastructure is no longer dependent on specific regions, and that the trend to circumvent geographical restrictions via cloud services and VPNs is accelerating. Attackers are increasingly using technologies such as cloud services and VPNs to circumvent geographical restrictions, and are using countries and regions that were not previously considered as relay points.
There have been reports that Russia and China in particular are using regions where cybersecurity is lagging behind, such as Africa, as a foothold for launching cyberattacks on other countries, such as the United States and Europe, and as a cover for further attacks, such as training cybercriminals locally.
Given this background, we are now in an era where we must pay attention not only to "where the attack is coming from" but also to "how the foundation of the attack is changing."

Furthermore, the continued increase in attacks on the PHP testing framework "PHPUnit," which has not received much attention, is also a cause for alarm. There are many cases where tools originally intended for testing environments remain in production environments, becoming a blind spot in security measures. There is concern that attacks targeting such "unanticipated vulnerabilities" will continue to expand in the future.

In order to respond quickly to threats that change daily, we will further strengthen our system for understanding attack trends and early detection of abnormal signs, thereby helping companies reduce security risks and operate their websites with peace of mind.

 

About Cyber Security Cloud, Inc.
Company name: Cyber Security Cloud, Inc.
Address: 13F JR Tokyu Meguro Building, 3-1-1 Kami-Osaki, Shinagawa-ku, Tokyo 141-0021
Representative: Representative Director, President and CEO Toshihiro Koike
Established: August 2010
URL: https://www.cscloud.co.jp

With the mission of "creating a safe and secure cyberspace for people all over the world," we are a Japanese security manufacturer that provides web application security services utilizing world-leading cyber threat intelligence, as well as vulnerability information collection and management tools and fully managed security services for cloud environments. As one of the global companies in cybersecurity, we will contribute to solving social issues related to cybersecurity and providing added value to society.