Out of curiosity, what is the modern state of DDoS? My current understanding is that you get massive botnets largely built up of vulnerable IoT devices.
That's still a good chunk of traffic, but there's also compromised firewalls, VPNs, and random servers. The device types themselves change as new exploits are discovered. Because Twitter still uses their own data centers they could be subject to various amplification attacks as well. But if what he says is true and it's all coming from one country then that is trivial to block at ingress.