Aisuru is a financially motivated cybercriminal group operating large-scale Internet-of-Things botnets and selling distributed denial-of-service (DDoS) attack capacity. Also tracked as AISURU, Aisuru Botnet, and Aisuru Botnet Operators, its botnet has historically used the names NAKOTNE and AISURA. Aisuru compromises routers, digital video recorders, IP cameras, wireless access points, and gateways, using the resulting infrastructure for hyper-volumetric attacks against gaming platforms, hosting and information-technology services, and telecommunications providers. Its attacks have also targeted the United States Department of Defense network. The group also operates Kimwolf, an Android-focused botnet primarily infecting residential TV boxes, smart TVs, and related devices. Shared distribution scripts, APK signing certificates, payload packaging, and infrastructure establish the operational relationship between Aisuru and Kimwolf. The two botnets have coexisted on compromised devices. Kimwolf supports DDoS attacks, TCP and UDP proxy forwarding, reverse shells, command execution, and file management, enabling both attack-for-hire services and monetization of compromised residential bandwidth. Its evasion and infrastructure-resilience mechanisms include encrypted strings, process masquerading, TLS communications, DNS over TLS, encoded command-and-control addresses, and Ethereum Name Service records. Android loaders use boot-triggered execution for persistence. Aisuru has been linked to DDoS attacks reaching 29.7 Tbps, while combined Aisuru/Kimwolf activity reached 31.4 Tbps during the December 2025 campaign known as The Night Before Christmas. Estimates placed Aisuru's population at up to four million compromised devices by the end of 2025. Kimwolf's observed DDoS targets were concentrated in the United States, China, France, Germany, and Canada. On March 19, 2026, authorities from the United States, Canada, and Germany disrupted command-and-control infrastructure used by Aisuru, Kimwolf, JackSkid, and Mossad. JackSkid shares Aisuru development-lineage characteristics but is tracked as a distinct botnet.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed as the botnet responsible for a record-breaking 31.4 Tbps DDoS attack and associated with terabit-scale distributed denial-of-service activity.
A botnet associated with multiple daily 1 Tbps DDoS attacks and a large device footprint; mentioned as background context in discussion of hyper-volumetric DDoS activity.
Infrastructure overlap with TuxBot through shared hosting and certificate artifacts; not stated to be the same malware/codebase.
Referenced as a malware/tooling lineage and shared infrastructure element associated with the TuxBot operator's ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.