Sound of Interference: Electromagnetic Eavesdropping Attack on Digital Microphones Using Pulse Density Modulation
Arifu Onishi
34th USENIX Security Symposium (USENIX Security '25) · Day 2 · Hardware Security 2
Overview
This article delves into the findings of a comprehensive research paper presented at USENIX Security, titled "Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services." Authored by a collaborative team of researchers from the University of Cambridge, University of Edinburgh, University of Strathclyde, and University of Illinois Chicago, the paper provides a multi-faceted analysis of the largest global intervention against DDoS-for-hire (also known as booter or stresser) services to date. The study, which commenced in December 2022, evaluates the effectiveness of coordinated law enforcement actions, combining infrastructure takedowns with sophisticated digital influence tactics.
Read the paper · Download the PDF (PDF) · Slides
Paper abstract
Law enforcement and private-sector partners have in recent years conducted various interventions to disrupt the DDoS-for-hire market. Drawing on multiple quantitative datasets, including web traffic and ground-truth visits to seized websites, millions of DDoS attack records from academic, industry, and self-reported statistics, along with chats on underground forums and Telegram channels, we assess the effects of an ongoing global intervention against DDoS-for-hire services since December 2022. This is the most extensive booter takedown to date conducted, combining targeting infrastructure with digital influence tactics in a concerted effort by law enforcement across several countries with two waves of website takedowns and the use of deceptive domains. We found over half of the seized sites in the first wave returned within a median of one day, while all booters seized in the second wave returned within a median of two days. Re-emerged booter domains, despite closely resembling old ones, struggled to attract visitors (80–90% traffic reduction). While the first wave cut the global DDoS attack volume by 20–40% with a statistically significant effect specifically on UDP-based DDoS attacks (commonly attributed to booters), the impact of the second wave appeared minimal. Underground discussions indicated a cumulative impact, leading to changes in user perceptions of safety and causing some operators to leave the market. Despite the extensive intervention efforts, all DDoS datasets consistently suggest that the illicit market is fairly resilient, with an overall short-lived effect on the global DDoS attack volume lasting for at most only around six weeks.

Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services
Speakers: Anh V. Vu (University of Cambridge); Ben Collier (University of Edinburgh); Daniel R. Thomas (University of Strathclyde); John Kristoff (University of Illinois Chicago); Richard Clayton (University of Cambridge); Alice Hutchings (University of Cambridge)
Conference: USENIX Security
Paper PDF: https://www.usenix.org/system/files/usenixsecurity25-vu.pdf
Overview
This article delves into the findings of a comprehensive research paper presented at USENIX Security, titled "Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services." Authored by a collaborative team of researchers from the University of Cambridge, University of Edinburgh, University of Strathclyde, and University of Illinois Chicago, the paper provides a multi-faceted analysis of the largest global intervention against DDoS-for-hire (also known as booter or stresser) services to date. The study, which commenced in December 2022, evaluates the effectiveness of coordinated law enforcement actions, combining infrastructure takedowns with sophisticated digital influence tactics.
The significance of this research lies in its empirical, data-driven assessment of cybercrime market disruption. By leveraging diverse quantitative datasets—including web traffic, ground-truth visits to seized websites, millions of DDoS attack records, and communications on underground forums and Telegram channels—the authors offer unique insights into the immediate and long-term impacts of such interventions. The paper critically examines how resilient the illicit DDoS-for-hire market is, how operators and users adapt, and what implications these findings hold for future law enforcement strategies.
Ultimately, the research highlights the complex "cat-and-mouse" dynamic inherent in combating cybercrime. While the intervention achieved notable short-term successes, particularly in reducing specific types of DDoS attacks and shifting user perceptions, the market's underlying resilience and rapid adaptation mechanisms underscore the continuous challenge faced by law enforcement and private sector partners in dismantling these persistent threats.
Background
The cybercrime ecosystem has undergone a significant transformation over the past two decades, largely driven by the industrialisation of economic cybercrime. This shift has seen the emergence of as-a-service models, where complex malicious capabilities are packaged into user-friendly commercial offerings. Among the most prevalent of these are DDoS-for-hire services, or "booters" and "stressers," which enable individuals with minimal technical skill to launch Distributed Denial of Service (DDoS) attacks for as little as a few dollars per month (Section 1). These services, often falsely advertised as legitimate network stress-testing tools, are predominantly used for illegal activities such as disrupting online games, targeting schools during exams, or gaining competitive advantages.
Common attack vectors leveraged by booters include reflective attacks exploiting UDP protocols like DNS, NTP, and LDAP. These attacks amplify small, spoofed packets into large responses directed at victims, exhausting bandwidth capacity and making attribution challenging. Booters also employ direct-path attacks such as SYN and ACK flooding, and application-layer attacks that mimic legitimate traffic using compromised machines (botnets) (Section 2). While individual booter attacks may not cripple major, well-protected sites, they are highly effective against home connections or unprotected servers, typically lasting 5-10 minutes. The financial sustainability of booters, with some earning hundreds of thousands of dollars, allows them to maintain infrastructure, despite payment methods shifting from credit cards to cryptocurrencies due to prior interventions.
Previous disruption efforts have varied in scope and success. In 2017, PayPal's shutdown of booter-associated accounts forced a widespread switch to crypto payments. The popular hacking forum HACK FORUMS banned booter advertisements in 2016, leading to a more dispersed customer base communicating via Discord and Telegram. Law enforcement has also conducted significant operations, notably a December 2018 global takedown (Operation PowerOFF) that seized 15 domains and resulted in arrests. This intervention caused a temporary, short-lived reduction in UDP amplification and self-reported DDoS attacks (Section 2). Influence campaigns, such as the UK National Crime Agency (NCA) using Google ads to warn users, have also shown short-term efficacy in reducing demand.
The intervention analysed in this paper represents an escalation of these efforts. It was launched in late 2022, four years after Operation PowerOFF, and was designed to be more extensive and persistent. The campaign involved the FBI, NCA, and Dutch Police, collaborating with academics and private industry. The first wave, on December 14, 2022, saw 49 domains of 48 of the largest booters seized and several arrests made. A second wave followed on May 5, 2023, seizing 13 more domains. This operation uniquely combined infrastructure targeting with digital influence tactics, including the deployment of deceptive sites (honeypots) by the NCA to attract and warn users, search engine ad campaigns informing users of illegality, and active monitoring and posting on forums and chat channels to disseminate information and warnings (Section 2).
Key Findings
The comprehensive analysis of the global takedown against DDoS-for-hire services revealed several critical findings regarding the market's resilience and the impact of intervention strategies:
- Rapid Resurrection: Over half (52%) of the 48 booters seized in the first wave returned online within a median of just one day (19 hours). For the second wave, all 11 seized booters resurrected, with a median return time of two days (42 hours). Booters seized in both waves exhibited even faster reinstallation times, with a median of just one hour, indicating increased preparedness (Section 4).
- Traffic Reduction for Re-emerged Domains: Despite quick resurrections and closely resembling old domains, re-emerged booter websites struggled significantly to attract visitors. They experienced an 80–90% reduction in web traffic compared to pre-takedown levels, suggesting a positive impact on the supply side's ability to attract new and returning users (Section 5).
- Short-Lived Impact on Global DDoS Volume: The first wave of takedowns resulted in a statistically significant cut of 20–40% in global DDoS attack volume, particularly affecting UDP-based DDoS attacks, which are commonly attributed to booters. However, this impact was short-lived, with attack volumes consistently recovering across all datasets within at most six weeks (Section 5). The second wave's impact on overall attack volume appeared minimal.
- Shifting User Perceptions and Operator Behavior: Underground discussions on forums like HACK FORUMS and Telegram channels indicated a cumulative impact on the community. There was a notable increase in the perception of risk and the illegality of booting, with less prevalence of the narrative that these services are legal or ignored. Some booter operators explicitly announced their departure from the market, citing risk and unsustainability (Section 5).
- Limited Traffic Displacement to Deceptive Sites: The NCA's deceptive domains, part of the influence campaign, attracted a peak of 1,234 visits on December 30, 2022 (around one-third of visits to seized/resurrected domains on that day). However, traffic to these sites dropped quickly and they became largely inactive after about a week, indicating a notable but brief effect on confusing the UK market (Section 5).
- Persistent Demand and Market Adaptation: The contrast between decreasing booter traffic to re-emerged domains and the recovery of overall DDoS attack volume suggests that suppressing the supply side alone is insufficient. The demand for DDoS services likely persists, leading to the emergence of new, smaller booters or users migrating to alternative services and attack vectors (Section 6).
Technical Deep Dive
The research employed a multi-methodological approach, combining extensive quantitative data collection with qualitative analysis of underground communications to provide a holistic view of the DDoS-for-hire market and the impact of law enforcement interventions (Section 3).
Data Collection and Methodology
The study's backbone was a unique collaboration with law enforcement, enabling direct observation and data collection from the intervention itself. This included:
- Ground-truth Traffic Collection: Seized booter domains were redirected to a landing page hosted by the researchers using Cloudflare serverless. This page displayed takedown messages and logged all traffic, providing ground-truth insights into user visits to seized and later, NCA-deployed deceptive domains. Data cleaning involved removing API calls, link prefetching, and traffic from known search engine crawlers and bots (e.g., Google, Bing, SemrushBot, UptimeRobot), which accounted for over 30% of sessions. User sessions were defined as a series of requests from an IP address to a domain within a 30-minute inactivity window, similar to industry standards. This dataset spanned from December 14, 2022, to July 31, 2023, encompassing 20.7 million raw events and 2.7 million sessions (Section 3).
- Web Traffic Analytics (Similarweb): To estimate historical traffic and trends for both seized and newly emerged domains, Similarweb analytics were used. This platform aggregates anonymous statistics from various sources. The reliability of Similarweb data was validated against the ground-truth traffic, showing a strong positive Pearson correlation (r = 0.81), confirming its utility for broader trend analysis (Section 3).
- DDoS Attack Datasets: Four distinct datasets were used to provide comprehensive coverage of DDoS activity:
- HOPSCOTCH Dataset: Collected since 2014 by the Cambridge Cybercrime Centre, this global honeypot imitates UDP protocols susceptible to reflective attacks. It records events when attackers scan for reflectors, providing a partial view focused on booter-generated Layer 4 UDP attacks. The dataset comprised 4.6 million DDoS attack records (Section 3).
- AMPPOT Dataset: Similar to HOPSCOTCH, AMPPOT is another UDP amplification DDoS attack honeypot, emulating protocols like NTP, DNS, SSDP, LDAP, and CHARGEN. Deployed across 21 instances globally, it captured 9.8 million DDoS attack records (Section 3).
- NETSCOUT Dataset: Provided by NETSCOUT, a DDoS mitigation service provider, this dataset offers a broader view, covering not only booter-generated attacks but also TCP-based and direct-path attacks (e.g., SYN-, ACK-, and GRE-flooding). It includes 32.9 million aggregated counts of medium to high severity attack alerts, derived from NetFlow data, though it lacks country-specific views (Section 3).
- Self-reported Statistics: Researchers manually collected weekly statistics from 207 booters, including advertised services, active customers, and successful attacks. Prior work validated these statistics as reflecting naturally-occurring data, despite potential incentives for manipulation. This dataset provided insights into overall attack volumes and market share dynamics (Section 3).
- Underground Communications:
- Underground Forums (HACK FORUMS): Posts related to DDoS, booters, and interventions were extracted from HACK FORUMS (1,704 posts from 714 users) from October 2022 to September 2023, using keywords like 'booter', 'stresser', 'ddos', 'fbi', and 'nca'. This provided qualitative insights into community perceptions and discussions (Section 3).
- Chat Channels (Telegram): Researchers monitored 52 Telegram channels of working booters, collecting 34,438 messages, 5,246 replies, and 6,290 emoji reactions. This data was crucial for tracking booter resurrections and understanding user and operator reactions to takedowns (Section 3).
Takedowns and Resurrections
The intervention involved two waves: the first on December 14, 2022 (49 domains), and the second on May 5, 2023 (13 domains). Analysis showed a significant reliance on US-based domain registrars like Namecheap, particularly in the first wave (82% by Namecheap, 88% in the US). While many booters quickly resurrected, the second wave saw all seized booters reappear, often with new domains closely resembling old ones. The median reinstallation time (from domain registration to online) was notably shorter in the second wave (2 hours vs. 8 hours in the first wave), indicating increased operator preparedness (Section 4).
User Access Patterns and Behavior
Ground-truth data revealed several interesting user behaviors:
- Session Duration and Requests: While most sessions were short, lasting a few seconds, there were spikes in average session duration (up to 150 seconds) and requests per session following takedowns, suggesting users were actively attempting to access seized sites or navigate alternatives.
- User Agents and Obfuscation: A spike in user agent changes was observed on takedown days, indicating users trying different browsers or faking agents to bypass blocks. However, proxy usage remained low, with only 2.28% of sessions (61k out of 2.7M) using public proxies on first access. The majority of proxied requests (97.34%) originated from data centers and web hostings, not residential proxies or Tor exit nodes. This suggests a relatively technically unskilled user base lacking advanced operational security practices.
- Geographic Distribution: US visitors constituted the largest share (37.43%), followed by China (5.51%), Germany (5.04%), and the UK (4.55%), among others.
- Technology Use: PC users dominated (77.63%), with Chrome and Firefox being the most popular browsers, a pattern distinct from global averages and potentially indicative of desktop gaming demographics (Section 4).
Navigation and Reselling Capacity
The study found that a quarter of unique IP addresses visited multiple domains after a seizure, indicating prior awareness of alternative booters. However, users primarily navigated towards smaller booters rather than the largest ones (Section 4). The research also uncovered evidence of reselling capacity, where larger booters provide APIs to smaller, second-tier services. API call sessions saw a sharp 80% decline after the first wave and a 90% drop in calling users. A notable exception was a single user or reseller making repeated API requests for 180-minute TCP-based attacks for months after the takedown, potentially unaware or unconcerned by the intervention (Section 4).
Longitudinal Effects and Statistical Modeling
To precisely quantify the impact of takedowns amidst other events and seasonal effects, the researchers employed negative binomial regression for interrupted time series analysis. This statistical technique models weekly attack counts, accounting for underlying trends, random variation, and seasonal fluctuations. The models were theory-driven, incorporating intervention components and durations based on prior knowledge (Section 5).
- First Wave Impact: Across HOPSCOTCH, AMPPOT, and NETSCOUT datasets, the first wave showed a statistically significant drop in weekly UDP-based attack counts (e.g., from 45k to 25k in HOPSCOTCH, 80k to 40k in AMPPOT, 100k to 70k in NETSCOUT). The self-reported statistics also showed a significant drop from 55M to 45M total weekly attacks. This impact lasted approximately six weeks before attack volumes rebounded, sometimes surpassing pre-takedown levels (Section 5).
- Second Wave Impact: The second wave consistently showed minimal or statistically insignificant effects on DDoS attack volumes across all datasets (Section 5).
- Market Structure: Unlike the 2018 takedown, which saw larger booters absorb market share, this intervention did not result in a "monopoly effect." Major booters that survived did not significantly grow, and the recovery in attack volume was attributed to the emergence of smaller, new booters (Section 5).
Demo / Proof of Concept
While this research is presented as a peer-reviewed paper rather than a live conference talk with a traditional software demonstration, the closest equivalent to a "proof of concept" or empirical demonstration lies in the ground-truth traffic collection methodology. The collaboration with law enforcement allowed the researchers to directly observe the immediate aftermath of the takedowns.
Specifically, when booter domains were seized, law enforcement redirected them to splash pages hosted by the research team via Cloudflare serverless. These pages displayed warnings about the illegality of DDoS activities and logged all incoming traffic. This setup provided a unique, real-world "demonstration" of user behavior post-takedown. The researchers could track:
- The volume of users attempting to access the seized sites.
- How quickly users abandoned these sites or attempted to navigate to other services.
- The characteristics of these users, including their geographical location, browser/OS, and whether they employed proxies.
- The immediate impact on API calls to these services, indicating disruption to reselling operations.
This direct observation of user interaction with the law enforcement-controlled pages served as a powerful, real-time empirical "demo" of the intervention's initial effects on the user base and the immediate supply-side disruption. It provided concrete evidence of traffic displacement and the immediate behavioral responses of the booter community, which would otherwise be unobservable.
Defensive Implications
The findings from this extensive global takedown offer crucial insights for both law enforcement agencies and organizations seeking to defend against DDoS attacks.
For Law Enforcement and Interventionists:
- Sustained, Multi-pronged Approach is Key: While single takedowns can achieve significant short-term disruption, especially against UDP-based attacks, the market's resilience means effects are short-lived (around six weeks). A sustained, multi-wave approach, combining infrastructure targeting with digital influence operations, is more effective in creating cumulative impact and long-term friction (Section 6).
- Digital Influence Tactics are Valuable: Deploying deceptive sites (honeypots), running targeted search engine advertisements, and actively engaging in underground forums and chat channels can influence user perceptions of risk, deter new users, and encourage some operators to exit the market. These tactics, while not always leading to direct arrests, contribute to weakening trust and increasing perceived risk within the cybercrime ecosystem (Section 6).
- Focus on Frictious Interventions: The goal should be to continuously increase the friction involved in operating and accessing DDoS-for-hire services. This includes making them less accessible (through takedowns and domain seizures), less reliable (due to repeated disruptions), less advertisable (through search engine censorship), and less trustworthy (by sowing doubt and increasing risk perception) (Section 7).
- Target Seasonal Peaks: Interventions timed around periods of increased DDoS activity, such as school holidays or Christmas, can maximize disruption when demand is highest, making the as-a-service market untenable at scale during critical times (Section 7).
- Address Demand Side: Suppressing the supply side alone is insufficient as demand persists. Future strategies should consider how to further reduce user demand, perhaps through continued educational campaigns on legal consequences and risk.
For Organizations and Network Defenders:
- Assume Persistent Threat: Despite law enforcement efforts, DDoS-for-hire services remain resilient. Organizations should not become complacent; the overall long-term landscape of DDoS attacks is not significantly influenced by these takedowns (Section 5).
- Implement Robust DDoS Mitigation: Modern sites must be guarded by third-party security layers such as Cloudflare and DDoS-Guard that can filter and drop malicious packets. These services are crucial for protecting against the common UDP-based reflective and amplification attacks frequently launched by booters, as well as TCP-based and application-layer attacks (Section 2).
- Prepare for UDP-Based Attacks: The research consistently shows that booters primarily leverage UDP protocols. Defenders should prioritize mitigation strategies specifically designed to counter UDP amplification and reflective attacks, which aim to exhaust bandwidth capacity (Section 2).
- Monitor for Short, Intense Attacks: Booter-generated attacks are typically short-lived (5-10 minutes). Organizations need rapid detection and response mechanisms to counter these burst attacks before they cause significant disruption, even if they are not always powerful enough to shut down major sites (Section 2).
- Understand User Behavior: The low adoption of advanced operational security (like Tor usage) among booter users suggests that basic IP-based blocking and geofencing might still be effective against a segment of attackers, though this should not be the sole defense (Section 4).
Key Takeaways
- The global DDoS-for-hire market demonstrates significant resilience, with services often resurrecting within days after extensive law enforcement takedowns.
- While the first wave of interventions significantly reduced UDP-based DDoS attack volumes (20-40%), this impact was short-lived, lasting at most around six weeks. The second wave had minimal effect.
- Re-emerged booter domains, despite resembling old ones, struggled to regain pre-takedown traffic levels, experiencing 80-90% reductions, indicating a positive impact on the supply side's ability to attract users.
- Digital influence tactics, such as deceptive sites and forum engagement, contributed to a shift in user perceptions, increasing awareness of illegality and perceived risk, and prompting some operators to exit the market.
- The persistence of demand for DDoS attacks, coupled with the emergence of new, smaller booters, suggests that suppressing supply alone is insufficient; a continuous, multi-faceted strategy focused on increasing friction and addressing demand is necessary.
- Booter users generally exhibit low operational security, with minimal use of advanced anonymization tools like Tor, suggesting that targeted interventions can still effectively disrupt their activities.
About the Speaker(s)
The research paper "Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services" was a collaborative effort by a team of distinguished academics:
- Anh V. Vu is affiliated with the University of Cambridge.
- Ben Collier is associated with the University of Edinburgh.
- Daniel R. Thomas is a researcher at the University of Strathclyde.
- John Kristoff is a faculty member at the University of Illinois Chicago.
- Richard Clayton is affiliated with the University of Cambridge.
- Alice Hutchings is also associated with the University of Cambridge.
This diverse group of researchers, hailing from leading institutions across the UK and US, brings expertise in cybersecurity, cybercrime analysis, and network security, contributing to the comprehensive and interdisciplinary nature of this study. Their collective work focuses on understanding the dynamics of online illicit markets and evaluating the effectiveness of interventions against cybercrime.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Solid empirical work measuring what actually happens when law enforcement tries to burn down the booter market. The methodology is rigorous, the datasets are unique, and the conclusion is honest: we can hurt them, but we can't kill them. That's a finding worth having.
Heather Calloway (CISO) — SOLID
Rigorous empirical assessment of a major law enforcement intervention against DDoS-for-hire. Provides the kind of evidence-based analysis that should inform how we think about cybercrime disruption strategy—both its possibilities and its limits.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)