Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas Campaign, 1-4M Infected Android TVs, Operator 'Forky' Identified — Threadlinqs Intelligence
As of 2026-05-30, Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas Campaign, 1-4M Infected Android TVs, Operator 'Forky' Identified is a critical-severity malware threat attributed to Aisuru-Kimwolf (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0098 · Severity: CRITICAL · Status: RESOLVED · Category: MALWARE
Attribution: Aisuru-Kimwolf · N/A · FINANCIAL
The Aisuru-Kimwolf botnet launched a record-shattering 31.4 Tbps DDoS attack in Q4 2025, capping a year where DDoS attacks surged 121% to 47.1 million. Comprising an estimated 1-4 million
The Aisuru-Kimwolf botnet represents the apex of modern DDoS botnets, combining unprecedented volumetric capacity with a sophisticated evolution trajectory. First identified by QiAnXin XLab in August 2024 during a coordinated DDoS campaign targeting Steam and Perfect World gaming platforms during the Black Myth: Wukong launch, the botnet has undergone rapid iteration: AISURU (Aug 2024) → kitty (Oct 2024, simplified protocol with SOCKS5 proxying) → AIRASHI (Nov 2024+, RC4 string encryption, HMAC-SHA256 verification, ChaCha20 C2 encryption).
The botnet exploits a zero-day vulnerability in Cambium Networks cnPilot routers alongside numerous N-day vulnerabilities and Telnet default credential exploitation across IoT devices including cameras (HiSilicon), DVRs (TVT-NVMS 9000), and Android TV boxes. The operator, known as 'Forky' — a 21-year-old based in São Paulo, Brazil — operates a DDoS-for-hire service via Telegram at prices ranging from $150/day to $600/week, advertising attack capabilities of 1-3 Tbps (self-tested via third-party measurement services).
Cloudflare's 2025 Q4 DDoS Threat Report (published February 5, 2026) confirmed a record-setting 31.4 Tbps attack lasting just 35 seconds. Throughout 2025, DDoS attacks more than doubled to 47.1 million, with Cloudflare mitigating an average of 5,376 attacks every hour. The 'Night Before Christmas' campaign (beginning December 19, 2025) saw the Aisuru-Kimwolf botnet deliver 902 hyper-volumetric attacks with peak rates of 9 Bpps, 24 Tbps, and 205 Mrps — equivalent to the combined populations of the UK, Germany, and Spain simultaneously loading a webpage.
KrebsOnSecurity was hit with a 6.3 Tbps attack from Aisuru in May 2025 — 10x the 2016 Mirai attack that took KrebsOnSecurity offline for 4 days. Google Project Shield (protecting KrebsOnSecurity) confirmed it was the largest attack Google had ever handled. The botnet's traffic has caused widespread collateral Internet disruption across US ISPs even when those ISPs were not the intended targets.
Forky's infrastructure includes Botshield LTD (UK-registered, AS213613), which provides DDoS mitigation services while simultaneously operating the botnet — a brazen dual-use model. The FBI has seized multiple domains associated with Forky's operations (stresser.best, stresser.us) across Operation PowerOFF enforcement waves.
The evolution from Mirai's 1 Tbps record in 2016 to Aisuru's 31.4 Tbps in 2025 represents a 31x increase in peak DDoS capacity in under a decade. Hyper-volumetric attacks grew 700% in 2025, with most lasting under 35-45 seconds — too fast for human intervention or on-demand scrubbing services to activate.
Weaknesses (CWE)
CWE-798, CWE-1392, CWE-400
Target sectors: Telecommunications, Gaming, Financial Services, Hosting Providers, Generative AI, Gambling & Casinos, Critical Infrastructure
Target regions: Global, United States, China, Germany, Hong Kong, United Kingdom, Brazil
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1583.005, T1190, T1195.003, T1059.004, T1547, T1027.013, T1110.001, T1046, T1210, T1119