Aisuru is a Mirai-derived botnet first identified in August 2024 that compromises Linux-based routers, DVRs, and other connected devices, primarily through firmware vulnerabilities. It is operated for profit-driven distributed denial-of-service attacks and has expanded into traffic proxying and Android device recruitment. Its development lineage includes the kitty and AIRASHI variants. Aisuru is closely linked to the Android-focused Kimwolf botnet through shared distribution scripts, signing certificates, payload infrastructure, and deployment on the same compromised devices.
Aisuru primarily launches direct volumetric UDP and TCP floods. Operators can configure attack targets, packet sizes, timing, payloads, and protocol-specific options, and chain short commands into sustained attack sessions. Its targets include technology, gaming, finance, education, and government organizations worldwide. The combined Aisuru/Kimwolf ecosystem has been associated with record-breaking DDoS attacks, including a 31.4-terabit-per-second attack mitigated in December 2025.
Aisuru conceals backend command-and-control information in encoded DNS TXT records. Its communication protocol exchanges an RC4-wrapped ChaCha20 key and nonce before using ChaCha20-encrypted communications. A backconnect proxy capability allows infected devices to relay operator traffic. In June 2026, operators used this functionality to scan local Android Debug Bridge services and install an Android application that deployed a TCP/UDP proxy bot, extending compromise into locally reachable devices.
Authorities in the United States, Germany, and Canada disrupted Aisuru command-and-control infrastructure on March 19, 2026. Observed attack activity stopped for approximately three weeks before resuming at a reduced rate, demonstrating that the disruption did not permanently eliminate the botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
„Најраниот пронајден примерок, кој ја таргетира x86 архитектурата со експлоатација на Dirty COW , укажува дека оваа фамилија еволуирала од традиционална Linux експлоатација кон актуелниот Android модел на ширење базиран на ADB“
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“These two major botnets propagated through the same infection scripts between September and November, coexisting in the same batch of devices. They actually belong to the same hacker group.”
Shared infrastructure ties the operator to the Keksec ecosystem, home to Kaitori and AISURU tooling.
Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code.
The biggest change, according to the report, is a new flood method built on HTTP/2, the protocol that carries most web traffic today.
“The bot first resolves its C2 from a DNS TXT dead-drop” and “dead drop domains ... update information in their TXT records with base64 and XOR encoded information to give the real backend IPs back to the bot.”
Published third-party research places malware infrastructure in SYSECT-routed prefixes: Kimwolf v7 C2 endpoints in 212.193.31.0/24; an Aisuru-matched sample contacting 147.45.44.34:8001; and a possible Sliver C2 at 89.19.220.70:4443. Bitsight also documented Aisuru/Kimwolf proxy infrastructure in ML Cloud-geofeed-declared ranges.
Tor resolves that address through its own network rather than the ordinary domain system, and it hides where the server actually sits, which leaves investigators without a host to contact.
“This payload opens a raw netcat communication with the IP presented and downloads an APK that is then installed and initiated on the system.”
The malware now looks up its command address in the Ethereum Name Service, a directory that lives on the Ethereum blockchain.
“Behind the domains we counted 259 distinct C2 IPs” and “the operators kept trying to stand up replacements.”
generic malware, such as botnets, is increasingly targeting OT devices... exploit OT default credentials and wipe data directories
“the ATTACK command (which instructs the bot to carry out a DDoS attack)” and “Over four months of tracking we logged 66,596 DDoS attack commands.”
135 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
184 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Large-scale DDoS botnet closely linked to Kimwolf and associated with attacks approaching 30 terabits per second. The article reports a March 2026 infrastructure seizure followed by rapid rebuilding.
Discussed alongside Kimwolf as botnet infrastructure drawing on millions of unofficial Android streaming boxes for massive DDoS attacks. The guide also states that Aisuru accounts for roughly one-third of global DDoS traffic.
Botnet-associated infrastructure was reported in multiple ML Cloud-declared or SYSECT-routed prefixes, including an ADB-exploitation payload host and proxy/C2 infrastructure. The article treats the sandbox detection as unverified and does not attribute botnet operation to the network providers.
A super-botnet cited as contributing to the increasing intensity of DDoS attacks against European organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.