Aisuru is a Mirai-lineage IoT botnet associated with large-scale distributed denial-of-service activity and opportunistic compromise of exposed internet-connected devices. It has been active since at least 2020 and has been linked to attacks leveraging insecure consumer IoT equipment as well as exposed operational technology and industrial control assets that still use default credentials. Reported descendants and splinter variants include kitty, AIRASHI, and Kimwolf, and multiple later botnet frameworks have been assessed to share lineage or tooling overlap with Aisuru within the broader Keksec ecosystem.
Aisuru is primarily known for DDoS operations, including very large volumetric floods measured in the multi-terabit range. Observed variants and related branches support a range of attack methods and increasingly resilient command-and-control designs. Later lineage variants introduced features such as encrypted or obfuscated communications, DNS-based C2 discovery, reverse shell access, proxy functionality, and fallback mechanisms intended to complicate disruption. Some reporting also ties Aisuru-linked operations to residential proxy abuse and profit-driven botnet services beyond pure DDoS.
Propagation has relied on scanning for exposed services, exploitation of known vulnerabilities, and abuse of weak or default credentials. Aisuru activity has been observed targeting Linux-based IoT and edge devices, including routers and other embedded systems, and separate reporting identifies Android TV-focused botnet activity as a related branch of the same lineage. In OT-relevant cases, Aisuru samples contained default credentials for specific PLC and industrial device families and included destructive logic that wiped certain device data directories, indicating that opportunistic botnet malware can pose operational risk to exposed industrial environments even when not purpose-built as OT malware.
Aisuru has been associated with globally distributed targeting across multiple sectors and countries. Public reporting links the botnet to attacks against gaming infrastructure, broad internet-facing services, and other high-availability targets. Law-enforcement actions in 2026 targeted Aisuru and related botnets after authorities assessed that the broader cluster had compromised millions of devices. Despite disruption efforts, the malware family’s lineage continued through successor and splinter variants, underscoring its role as a durable and evolving IoT botnet ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
„Најраниот пронајден примерок, кој ја таргетира x86 архитектурата со експлоатација на Dirty COW , укажува дека оваа фамилија еволуирала од традиционална Linux експлоатација кон актуелниот Android модел на ширење базиран на ADB“
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shared infrastructure ties the operator to the Keksec ecosystem, home to Kaitori and AISURU tooling.
Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code.
The biggest change, according to the report, is a new flood method built on HTTP/2, the protocol that carries most web traffic today.
Потоа инсталира малициозен софтвер способен за изведување DDoS напади и за претворање на уредот во реле преку кое се пренасочува злонамерен сообраќај.
Tor resolves that address through its own network rather than the ordinary domain system, and it hides where the server actually sits, which leaves investigators without a host to contact.
generic malware, such as botnets, is increasingly targeting OT devices... exploit OT default credentials and wipe data directories
In August 2024, we at XLab observed a premeditated large-scale DDoS attack targeting the distribution platforms of the Chinese game Black Myth: Wukong — Steam and Perfect World.
105 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
172 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mirai descendant mentioned only as background example of other variants targeted by law enforcement.
Botnet associated with record-breaking DDoS floods, including a 31.4 Tbps attack referenced in the article.
Related Linux counterpart botnet linked to Kimwolf and associated with large-scale DDoS activity and shared botnet infrastructure/operations.
A record-setting DDoS botnet referenced as the predecessor/origin from which Kimwolf splintered.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.