What is a ransom DDoS (RDDoS) attack?
A ransom DDoS attack, or RDDoS, is an extortion attempt in which criminals demand payment under threat of flooding an organization's services with traffic and taking them offline. The demand usually arrives by email, claims access to a large botnet, sets a deadline, and asks for cryptocurrency. Sometimes a short burst of traffic accompanies the message as a demonstration. Often nothing does. That last point matters. Sending an extortion email requires no DDoS capability, so many RDDoS demands come from actors who cannot carry out the threat. The organization receiving the message therefore has two problems to solve: assess whether the threat is credible and prepare for the availability impact if an attack does happen. This page explains how RDDoS works, how it differs from DDoS and ransomware, how to weigh a demand, and how to respond without making a rushed payment decision.
Key takeaways
- RDDoS is extortion based on a threat to availability. The sender says that services will go offline unless the organization pays. No access to the organization's systems is required.
- Many demands are bluffs. Sending the email costs almost nothing and does not require a botnet, so a large number of threats are never followed by an attack.
- The impact is downtime, not encrypted data. RDDoS targets the availability of online services, while ransomware targets systems and data through an intrusion.
- Impersonation is common. Extortionists often borrow the name of a well-known group, which can create an appearance of capability without proving it.
- Payment is not a reliable solution. It provides no guarantee that an attack will stop and can identify the organization as a willing payer.
How an RDDoS extortion attempt works
The pattern is consistent enough to recognize once the stages are understood:
- The demand arrives. An email, and sometimes a message submitted through a contact form, warns that the organization's services will be taken offline unless payment is made. It typically claims access to a botnet capable of overwhelming any defense.
- A deadline is set. The deadline is usually short, often a few days, and the amount may increase if it passes. Urgency is the mechanism. The sender wants a decision made under pressure rather than after analysis.
- A demonstration may follow. A brief, comparatively small burst of traffic against a public service may be used to show capability. Its presence matters, and so does its absence.
- Payment is demanded in cryptocurrency. This makes recovery of funds unlikely and offers no accountability if the sender promises to withdraw the threat.
- The attack may happen. Some demands are followed by a DDoS attack. In other cases, an organization that pays is contacted again because it has demonstrated that it will pay.
Sectors that depend on continuous online availability are common targets, including online retail, financial services, gambling, and gaming platforms. The reason is straightforward: extortion only works when downtime is expensive.
RDDoS, DDoS, and ransomware compared
These terms are often conflated, but they describe different attacks and require different decisions.
The practical distinction is access. Ransomware requires the attacker to enter the environment, which creates a chain of activity that defenders can investigate. RDDoS requires only a way to contact the organization and the ability, real or claimed, to generate traffic. The response therefore combines traffic-layer mitigation with threat assessment and a documented decision process.
Why many RDDoS threats are bluffs
A DDoS extortion campaign can be run by anyone with an email list. It requires no access to the target, no infrastructure, and no history of conducting a DDoS attack. The cost of sending thousands of messages is close to zero, and a small number of payments can make mass-mailed extortion profitable even when the sender has no capability behind it.
That does not make every demand safe to ignore. An organization cannot establish credibility from the message alone, but it can weigh several signals:
- Was there a demonstration? An actor that has generated traffic against the organization's infrastructure has shown more than an email can show. The absence of a demonstration strongly suggests an empty threat, but does not prove it.
- Is the message specific? Generic wording, no reference to actual services, and a templated tone suggest a mass mailing. A message naming specific systems suggests that someone conducted research.
- Is a famous group being impersonated? Extortionists routinely claim to be well-known groups. An actor with genuine capability has little reason to borrow another group's reputation, and established groups generally do not need to announce themselves by email before acting.
- Has the campaign appeared elsewhere? Threat intelligence can reveal the same wording and cryptocurrency address circulating across many organizations, which points to a mass campaign rather than a selected target.
- What is the actual exposure? The most useful question is what would happen if the threat were genuine. An organization that understands its mitigation capacity and has tested it can decide calmly.
What an extortion demand may be covering for
A denial-of-service incident, or the threat of one, can consume a security team's attention because the impact is immediate, visible, and measured in revenue. That makes it useful cover.
Reported patterns include DDoS activity accompanying or preceding intrusions, and denial of service used as an additional pressure tactic alongside data theft and encryption in some extortion operations. This does not mean that every RDDoS email conceals an intrusion. It means that an organization dealing with an availability incident should continue monitoring the rest of its environment. While everyone is focused on traffic graphs, quieter activity is less likely to receive attention.
How to respond to an RDDoS demand
The response is mostly procedural, and it is best decided before a demand arrives:
- Do not pay. Law enforcement agencies advise against payment. It provides no guarantee that the threat will be withdrawn and can mark the organization as a payer, inviting further demands.
- Preserve and report the demand. Keep the message, headers, and cryptocurrency address. Report it to national law enforcement or the relevant cyber authority, since reported campaigns help build the wider picture.
- Contact hosting and network providers. Ask what mitigation capacity is already available and what additional protection can be enabled. Organizations often have more capacity than they realize, or less than they assume.
- Check the campaign against threat intelligence. If the same wording and payment address are circulating widely, the organization may be one recipient of a mass mailing rather than a selected target.
- Decide who owns the decision. Agree in advance who handles the demand and what the answer will be. This removes much of the pressure created by the deadline.
- Keep watching the rest of the environment. Treat an availability event as a period of elevated security risk rather than the only activity taking place.
Why the available RDDoS guidance often emphasizes mitigation
Most detailed material on RDDoS comes from companies that sell DDoS mitigation. Their technical explanations and advice can be accurate, but their commercial position naturally emphasizes the need for mitigation. The possibility that a large share of demands are empty receives less attention because it reduces the urgency to buy a service.
Sekoia does not sell DDoS mitigation. That is a different category operating at the network and traffic layer, and organizations that need it should work with a provider that offers it. Sekoia's contribution is narrower: cyber threat intelligence from its in-house Threat Detection & Research (TDR) team can help identify active extortion campaigns and recognize when the same demand is being sent broadly. The Sekoia AI SOC platform correlates endpoint, identity, network, and cloud signals mapped to the MITRE ATT&CK framework, helping keep the rest of the environment visible during an availability incident.
Expert insight: RDDoS is a decision-making problem under a deadline
An RDDoS email is designed to force a decision before the organization has assessed its exposure. The deadline creates urgency, the cryptocurrency demand removes accountability, and the claim of a large botnet supplies the missing evidence. The organization that responds well is the one that has already decided who evaluates the demand, who contacts network providers, who reports it, and who makes the final decision.
The same preparation determines whether the organization can absorb a real attack. It needs a current view of critical services, tested traffic-mitigation capacity, communication plans, and monitoring that does not stop at the network edge. Threat intelligence can help distinguish a known mass campaign from a targeted demand, but it cannot replace an understanding of the organization's own exposure.
Sekoia is not an RDDoS mitigation platform. Its role is to add context to the extortion campaign and keep identity, endpoint, network, and cloud activity visible while the organization handles the availability risk. That distinction matters. RDDoS is mostly a decision-making problem wrapped in a deadline, and the best response begins before the email arrives.