Aisuru is a cybercrime-operated IoT botnet and DDoS-for-hire operation associated with some of the largest publicly reported distributed denial-of-service attacks observed in 2025 and 2026. It is commonly referenced alongside Kimwolf, which is widely described as an Android-focused branch or closely related component of the same botnet ecosystem, and it has also been linked by researchers to broader activity involving JackSkid and Mossad. Aisuru belongs to the Mirai-derived botnet landscape and has been described as part of a TurboMirai-class lineage, with later research placing JackSkid in the Aisuru development lineage and identifying infrastructure overlap with the Keksec ecosystem. The botnet primarily compromises internet-connected devices, including home and office routers, digital video recorders, IP cameras, gateways, Wi-Fi access points, and Android-based streaming devices. Reporting indicates that by the end of 2025 it had enrolled millions of devices globally and was capable of launching repeated hyper-volumetric attacks exceeding 1 Tbps, including record-setting campaigns in the roughly 30 Tbps range. Aisuru has been repeatedly characterized as a botnet-for-hire or DDoS-for-hire service that rented attack capacity to other criminals. Operationally, Aisuru is associated first and foremost with large-scale DDoS activity, especially network-layer flooding, but reporting also ties the operators to adjacent cybercrime services and techniques including residential proxy abuse, phishing, and credential stuffing. The ecosystem has been linked to compromised residential and consumer devices being used not only as attack nodes but also as proxy infrastructure and relay nodes. Gaming platforms, hosting providers, telecommunications, and broader internet-facing services have been repeatedly cited among prominent target categories. Aisuru has been connected to major attacks against gaming-related infrastructure and to record DDoS events mitigated by large cloud and network providers. Public reporting also attributes a late-2025 campaign known as “The Night Before Christmas” to Aisuru and Kimwolf, combining extreme network-layer floods with high-rate HTTP flooding. The botnet’s scale, rapid infrastructure rotation, and use of globally distributed compromised devices made it a significant threat to online services. In March 2026, authorities from the United States, Canada, and Germany, with private-sector support, disrupted infrastructure used by Aisuru together with Kimwolf, JackSkid, and Mossad by seizing domains and virtual servers used for command and control. Despite that action, subsequent reporting indicated regrouping and continued lineage activity in related clusters. Available reporting also suggests a likely operator nexus in Brazil for at least part of the Aisuru/Kimwolf activity, though the ecosystem appears internationally distributed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed as the botnet responsible for a record-breaking 31.4 Tbps DDoS attack and associated with terabit-scale distributed denial-of-service activity.
A botnet associated with multiple daily 1 Tbps DDoS attacks and a large device footprint; mentioned as background context in discussion of hyper-volumetric DDoS activity.
Infrastructure overlap with TuxBot through shared hosting and certificate artifacts; not stated to be the same malware/codebase.
Referenced as a malware/tooling lineage and shared infrastructure element associated with the TuxBot operator's ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.