Kaspersky Digital Footprint Intelligence reports that brokered DDoS attacks are priced on a case-by-case basis, ranging from $30 to $2,000. Pricing varies depending on factors such as the target, attack duration, service limits and available features.
In its new research, Kaspersky Digital Footprint Intelligence (DFI) experts examined how DDoS services are offered across the darknet, how different service models are priced and marketed, how competition shapes the market over time, and what behavioral patterns characterize the actors behind the DDoS supply. The experts analyzed more than 256,000 DDoS-related posts across the dark and deep web and identified 148 DDoS actors active since at least 2024. Three main DDoS attack models stand out: brokered attacks, where a third party is hired to carry out the attack, DDoS-as-a-Service, where users buy subscription to attack tools such as online control panels or Telegram bots, and in-house infrastructure, where actors run their own attack scripts or botnets. Among observed brokered actors, 65% advertised on cybercriminal forums, while 35% used Telegram and Discord.

Example of stresser panel subscription prices
The research reveals that DDoS activity is centered on two primary attack types: network-layer attacks, which seek to overwhelm infrastructure with heavy traffic, and application-layer attacks, which are aimed to disrupt websites and online services directly. Kaspersky DFI analysis shows that 74% of actors advertised L4 techniques such as TCP (Transmission Control Protocol), UDP (user datagram protocol), and DNS (Domain Name System) floods, while only 9% explicitly referred to standalone L3 methods. L7 attacks were the most widely offered, appearing in 92% of cases, underscoring both the broad availability of ready-made tools and the relative ease of targeting web-facing services. “DDoS attacks have become a more practical and accessible option for threat actors, largely because these services are cheap and easy to obtain. In some cases, the cost of launching an attack can be lower than a standard monthly streaming subscription, or even for a price of a cup of coffee. For businesses, this means DDoS readiness should be part of basic cybersecurity planning. It is equally important to understand the market behind these attacks, since stronger defense begins with a clearer understanding of the threat environment,” says João Pedro Brandão e Silva, Kaspersky Digital Footprint Intelligence analyst.
The full report is available here.
To strengthen the protection of your business, Kaspersky recommends the following:
Adopt a comprehensive digital risk protection service that monitors organizations' digital assets and detects threats across the surface, deep and dark web such as Kaspersky Digital Footprint Intelligence.
Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organization. The latestKaspersky Threat Intelligence provides them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.
Keep your employees informed about relevant threats.Kaspersky Automated Security Awareness Platform helps cultivate cyber-savvy behavior, including safe downloading practices.
Augment existing security controls with human-led detection and global threat intelligence through solutions like Kaspersky Managed Detection and Response (MDR), which offers 24/7 monitoring, detection, investigation and rapid response to sophisticated cyberattacks.