Threat reportMalwareTL-2026-0098

Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas Campaign, 1-4M Infected Android TVs, Operator 'Forky' Identified

criticalRESOLVED

Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS (TL-2026-0098) is a critical-severity malware campaign, first published 2026-02-05. It is attributed to Aisuru-Kimwolf with high confidence, maps to 24 MITRE ATT&CK techniques (T1027.013, T1046, T1053.003), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
1Aisuru-Kimwolf
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-0098

Threat ID
TL-2026-0098
Severity
CRITICAL
Status
RESOLVED
Category
MALWARE
First published
Last reviewed
Attribution
Aisuru-Kimwolf
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
Telecommunications, Gaming, Financial Services, Hosting Providers, Generative AI, Gambling & Casinos, Critical Infrastructure
Target regions
Global, United States, China, Germany, Hong Kong, United Kingdom, Brazil
Detection rules
9
Indicators of compromise
30

Malware and tooling in Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS

Malware and tooling: Aisuru-Kimwolf

How Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS works

The Aisuru-Kimwolf botnet launched a record-shattering 31.4 Tbps DDoS attack in Q4 2025, capping a year where DDoS attacks surged 121% to 47.1 million. Comprising an estimated 1-4 million malware-infected devices (primarily off-brand Android TVs), the botnet launched the 'Night Before Christmas' campaign on December 19, 2025, bombarding Cloudflare infrastructure and customers with 902 hyper-volumetric attacks averaging 53 per day. At its peak, the botnet delivered 29.7 Tbps (Q3) and 31.4 Tbps (Q4) — attacks so massive they caused 'widespread collateral Internet disruption in the US' simply by routing through ISPs that weren't even the target.

The Aisuru-Kimwolf botnet represents the apex of modern DDoS botnets, combining unprecedented volumetric capacity with a sophisticated evolution trajectory. First identified by QiAnXin XLab in August 2024 during a coordinated DDoS campaign targeting Steam and Perfect World gaming platforms during the Black Myth: Wukong launch, the botnet has undergone rapid iteration: AISURU (Aug 2024) → kitty (Oct 2024, simplified protocol with SOCKS5 proxying) → AIRASHI (Nov 2024+, RC4 string encryption, HMAC-SHA256 verification, ChaCha20 C2 encryption).

The botnet exploits a zero-day vulnerability in Cambium Networks cnPilot routers alongside numerous N-day vulnerabilities and Telnet default credential exploitation across IoT devices including cameras (HiSilicon), DVRs (TVT-NVMS 9000), and Android TV boxes. The operator, known as 'Forky' — a 21-year-old based in São Paulo, Brazil — operates a DDoS-for-hire service via Telegram at prices ranging from $150/day to $600/week, advertising attack capabilities of 1-3 Tbps (self-tested via third-party measurement services).

Cloudflare's 2025 Q4 DDoS Threat Report (published February 5, 2026) confirmed a record-setting 31.4 Tbps attack lasting just 35 seconds. Throughout 2025, DDoS attacks more than doubled to 47.1 million, with Cloudflare mitigating an average of 5,376 attacks every hour. The 'Night Before Christmas' campaign (beginning December 19, 2025) saw the Aisuru-Kimwolf botnet deliver 902 hyper-volumetric attacks with peak rates of 9 Bpps, 24 Tbps, and 205 Mrps — equivalent to the combined populations of the UK, Germany, and Spain simultaneously loading a webpage.

KrebsOnSecurity was hit with a 6.3 Tbps attack from Aisuru in May 2025 — 10x the 2016 Mirai attack that took KrebsOnSecurity offline for 4 days. Google Project Shield (protecting KrebsOnSecurity) confirmed it was the largest attack Google had ever handled. The botnet's traffic has caused widespread collateral Internet disruption across US ISPs even when those ISPs were not the intended targets.

Forky's infrastructure includes Botshield LTD (UK-registered, AS213613), which provides DDoS mitigation services while simultaneously operating the botnet — a brazen dual-use model. The FBI has seized multiple domains associated with Forky's operations (stresser.best, stresser.us) across Operation PowerOFF enforcement waves.

The evolution from Mirai's 1 Tbps record in 2016 to Aisuru's 31.4 Tbps in 2025 represents a 31x increase in peak DDoS capacity in under a decade. Hyper-volumetric attacks grew 700% in 2025, with most lasting under 35-45 seconds — too fast for human intervention or on-demand scrubbing services to activate.

MITRE ATT&CK techniques used in TL-2026-0098

defense-evasion

T1027.013 Encrypted/Encoded File; T1070.005 Network Share Connection Removal

discovery

T1046 Network Service Discovery

execution

T1053.003 Cron; T1059.004 Unix Shell

command-and-control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1568.002 Domain Generation Algorithms; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography

credential-access

T1110.001 Password Guessing

collection

T1119 Automated Collection

initial-access

T1190 Exploit Public-Facing Application; T1195.003 Compromise Hardware Supply Chain

lateral-movement

T1210 Exploitation of Remote Services

impact

T1485 Data Destruction; T1489 Service Stop; T1498.001 Direct Network Flood; T1498.002 Reflection Amplification; T1499 Endpoint Denial of Service

persistence

T1547 Boot or Logon Autostart Execution

resource-development

T1583.005 Botnet; T1584.005 Botnet

reconnaissance

T1595.001 Scanning IP Blocks

Remediation for Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS

Immediate actions

  • Deploy always-on, in-line DDoS protection — on-demand scrubbing centers cannot react within 35-second attack windows
  • Position all IoT devices behind firewalls — do not expose to public Internet
  • Change default credentials on all IoT devices (cameras, DVRs, routers, Android TV boxes)
  • Update firmware on Cambium Networks cnPilot routers (0-day in active exploitation)
  • Monitor for Aisuru/Airashi C2 domains (xlabsecurity.ru, cve-2021-36260.ru, honeybooterz.*)

Workarounds

  • Rate-limit UDP traffic on non-essential ports
  • Block inbound traffic from known Aisuru C2 infrastructure
  • Implement anycast routing for critical services to distribute attack traffic

Longer-term hardening

  • Transition from on-premise DDoS appliances to cloud-based volumetric protection — 31.4 Tbps exceeds all appliance capacity
  • Implement BCP38/BCP84 source address validation to prevent IP spoofing at network edge
  • Disable unnecessary UDP services (QOTD/port 17, Echo/port 7, Portmap/port 111, RIPv1/port 520)
  • Enforce IoT device lifecycle management — replace end-of-life devices that no longer receive security updates
  • Subscribe to Cloudflare DDoS Botnet Threat Feed (free for ISPs) to identify and remove botnet nodes
  • Implement network flow analysis to detect outbound DDoS participation from your own infrastructure

Weaknesses (CWE) in Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS

CWE-798, CWE-1392, CWE-400

Timeline of Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS

  • AISURU botnet first identified by QiAnXin XLab during coordinated DDoS campaign targeting Steam and Perfect World platforms during Black Myth: Wukong launch. Source: https://blog.xlab.qianxin.com/large-scale-botnet-airashi-en/
  • AISURU botnet temporarily ceased attack activities after XLab exposure. Source: QiAnXin XLab
  • AISURU updated and rebranded as 'kitty' variant — simplified network protocol, added SOCKS5 proxy C2 communication with 250 encoded proxies and 55 C2 addresses. Source: QiAnXin XLab
  • New variant 'AIRASHI' emerged with upgraded capabilities: RC4 string encryption, HMAC-SHA256 verification, ChaCha20 C2 encryption, proxy functionality. C2 domains mock security researchers (xlabresearch, foxthreatnointel). Source: QiAnXin XLab
  • AIRASHI botnet demonstrated stable 1-3 Tbps attack capability via third-party measurement service. Test recorded 3.11 Tbps peak (270.52 Mpps). Source: QiAnXin XLab Telegram monitoring
  • Cloudflare reports record 5.6 Tbps DDoS attack in Q4 2024, setting previous benchmark. Source: https://blog.cloudflare.com/ddos-threat-report-for-2024-q4/
  • Nokia/Wired report Eleven11bot (Mirai variant) delivering 6.5 Tbps attack — briefly held the public DDoS record. 30K+ compromised webcams/DVRs. Source: https://www.wired.com/story/eleven11bot-botnet-record-size-ddos-attacks/
  • Cloudflare Q1 2025 report: 20.5 million DDoS attacks blocked (358% YoY increase). 18-day campaign targeting Cloudflare infrastructure. 6.5 Tbps and 4.8 Bpps peak attacks. Source: https://blog.cloudflare.com/ddos-threat-report-for-2025-q1/
  • KrebsOnSecurity hit with 6.3 Tbps Aisuru attack — 10x the 2016 Mirai attack. Google Project Shield confirmed largest attack Google ever handled. Google/Cloudflare fingerprinted Aisuru as source. Source: https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with-near-record-6-3-tbps-ddos/
  • Cloudflare blocks record 7.3 Tbps DDoS attack targeting a hosting provider via Magic Transit. 37.4 TB delivered in 45 seconds. Multi-vector: 99.996% UDP floods + NTP/QOTD/Echo reflection. Source: https://blog.cloudflare.com/defending-the-internet-how-cloudflare-blocked-a-monumental-7-3-tbps-ddos/
  • Aisuru botnet causes 'widespread collateral Internet disruption' across US ISPs — ISPs were not even the intended targets, the attack traffic simply overwhelmed their infrastructure en route. Source: KrebsOnSecurity
  • Cloudflare Q3 2025 report: Aisuru dubbed 'the apex of botnets.' 1-4 million infected hosts. Record 29.7 Tbps and 14.1 Bpps. 1,304 hyper-volumetric Aisuru attacks in Q3. DDoS against AI companies surged 347% MoM. Source: https://blog.cloudflare.com/ddos-threat-report-2025-q3/
  • 'The Night Before Christmas' DDoS campaign begins: Aisuru-Kimwolf botnet bombards Cloudflare infrastructure and customers with 902 hyper-volumetric attacks (384 packet-intensive, 329 bit-intensive, 189 request-intensive). Peak: 9 Bpps, 24 Tbps, 205 Mrps. Source: https://blog.cloudflare.com/ddos-threat-report-2025-q4/
  • Cloudflare confirms record-shattering 31.4 Tbps DDoS attack mitigated in Q4 2025, lasting just 35 seconds. Hyper-volumetric attacks grew 700% over 2024. Source: https://blog.cloudflare.com/ddos-threat-report-2025-q4/
  • Cloudflare publishes Q4 2025 DDoS Threat Report confirming 47.1 million total DDoS attacks in 2025 (121% increase), 31.4 Tbps record, and Aisuru-Kimwolf as primary threat. Avg 5,376 attacks blocked per hour. Source: https://blog.cloudflare.com/ddos-threat-report-2025-q4/
  • As of 2026-05-29, the Aisuru-Kimwolf botnet is no longer operating: a coordinated US/German/Canadian operation seized its domains, servers, and C2 infrastructure on March 19-20, 2026, and operator Jacob Butler ("Dort") was arrested and charged in the US and Canada on May 20, 2026. The record 31.4 Tbps "Night Before Christmas" campaign has concluded; only successor Mirai variants persist (no CVE/KEV applies).

Sources cited for Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS

Detection coverage for TL-2026-0098

As of 2026-02-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0098 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats