NETSCOUT SYSTEMS has released fresh global threat intelligence revealing a sharp escalation in Distributed Denial of Service (DDoS) attacks across North Africa. Telecommunications operators, both wired and wireless, were the primary targets in Morocco, Tunisia, Libya and Algeria in the first half of 2025, with attackers favouring high-volume, multi-vector strikes designed to disrupt connectivity and destabilise network performance.
Morocco recorded more than 75,600 DDoS attacks, ranking second in Africa after South Africa. Tunisia endured the continent’s longest single attack, stretching nearly seven hours and peaking at 756.61 Gbps, the region’s highest recorded bandwidth. Libya suffered the second longest attack and the highest attack complexity, with 23 different vectors deployed in a single campaign. Algeria, while reporting far fewer incidents, still experienced severe peaks of 432.02 Gbps.
“Across the region, threat actors consistently targeted the telecommunications sector, unleashing high-volume, multi-vector attacks that disrupted connectivity and threatened service reliability. Overall though, the results show an interesting mix of patterns compared to our last Threat Intelligence Report,” said Bryan Hamman, Regional Director for Africa at NETSCOUT.
In Morocco, most attacks hit wireless telecoms carriers, with 64,517 incidents, followed by wired providers, research bodies, and even shoe retailers. Common vectors included TCP ACK, DNS amplification and SYN/ACK amplification. The country’s largest recorded event reached 158.88 Gbps and 17.74 Mpps. Tunisia faced fewer overall attacks than in late 2024, but the severity increased dramatically. Wired telecoms providers absorbed most hits, followed by wireless carriers and hotels. The country experienced the largest single attack in the region, peaking at 756.61 Gbps and 49.51 Mpps, with an aggregate burst reaching 27 Tbps in April 2025. Several attacks also exceeded 400 minutes in duration.
Libya’s attack patterns showed rising sophistication. While its maximum bandwidth was lower, 113.15 Gbps, the country saw a single attack with 23 vectors, signalling intense multi-layered techniques. Most strikes targeted wireless carriers, with unusual focus on gasoline stations also recorded. Algeria registered only 186 attacks in 1H 2025, but still faced large-scale peaks of 432.02 Gbps and 41.05 Mpps, largely aimed at telecoms infrastructure. DNS amplification dominated as the primary vector.
“North Africa is a prime example of how rapid digital growth attracts malicious activity. Attackers are increasing volumes in Morocco, deploying more complex multi-vector campaigns in Libya and launching enormous bandwidth events in Tunisia. Even Algeria, with fewer incidents, cannot ignore the scale of its biggest attacks. The lesson is clear: organisations must prepare for the scale and sophistication of today’s threats,” noted Hamman.
NETSCOUT maps DDoS activity through passive, active and reactive vantage points, providing visibility across the global threat landscape. It protects two-thirds of the routed IPv4 space and secures network edges carrying over 800 Tbps of peak global traffic in 1H 2025. The company monitors tens of thousands of attacks daily and tracks multiple botnets and DDoS-for-hire services leveraging millions of compromised devices worldwide.
















