# Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas Campaign, 1-4M Infected Android TVs, Operator 'Forky' Identified

> The Aisuru-Kimwolf botnet launched a record-shattering 31.4 Tbps DDoS attack in Q4 2025, capping a year where DDoS attacks surged 121% to 47.1 million. Comprising an estimated 1-4 million malware-infected devices (primarily off-brand Android TVs), the botnet launched the 'Night Before Christmas' campaign on December 19, 2025, bombarding Cloudflare infrastructure and customers with 902 hyper-volumetric attacks averaging 53 per day. At its peak, the botnet delivered 29.7 Tbps (Q3) and 31.4 Tbps (Q4) — attacks so massive they caused 'widespread collateral Internet disruption in the US' simply by routing through ISPs that weren't even the target.

- **Published:** 2026-02-05T18:00:00Z
- **Last reviewed:** 2026-02-05T18:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0098
- **ID:** TL-2026-0098
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** RESOLVED
- **Actor:** Aisuru-Kimwolf
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The Aisuru-Kimwolf botnet represents the apex of modern DDoS botnets, combining unprecedented volumetric capacity with a sophisticated evolution trajectory. First identified by QiAnXin XLab in August 2024 during a coordinated DDoS campaign targeting Steam and Perfect World gaming platforms during the Black Myth: Wukong launch, the botnet has undergone rapid iteration: AISURU (Aug 2024) → kitty (Oct 2024, simplified protocol with SOCKS5 proxying) → AIRASHI (Nov 2024+, RC4 string encryption, HMAC-SHA256 verification, ChaCha20 C2 encryption).

The botnet exploits a zero-day vulnerability in Cambium Networks cnPilot routers alongside numerous N-day vulnerabilities and Telnet default credential exploitation across IoT devices including cameras (HiSilicon), DVRs (TVT-NVMS 9000), and Android TV boxes. The operator, known as 'Forky' — a 21-year-old based in São Paulo, Brazil — operates a DDoS-for-hire service via Telegram at prices ranging from $150/day to $600/week, advertising attack capabilities of 1-3 Tbps (self-tested via third-party measurement services).

Cloudflare's 2025 Q4 DDoS Threat Report (published February 5, 2026) confirmed a record-setting 31.4 Tbps attack lasting just 35 seconds. Throughout 2025, DDoS attacks more than doubled to 47.1 million, with Cloudflare mitigating an average of 5,376 attacks every hour. The 'Night Before Christmas' campaign (beginning December 19, 2025) saw the Aisuru-Kimwolf botnet deliver 902 hyper-volumetric attacks with peak rates of 9 Bpps, 24 Tbps, and 205 Mrps — equivalent to the combined populations of the UK, Germany, and Spain simultaneously loading a webpage.

KrebsOnSecurity was hit with a 6.3 Tbps attack from Aisuru in May 2025 — 10x the 2016 Mirai attack that took KrebsOnSecurity offline for 4 days. Google Project Shield (protecting KrebsOnSecurity) confirmed it was the largest attack Google had ever handled. The botnet's traffic has caused widespread collateral Internet disruption across US ISPs even when those ISPs were not the intended targets.

Forky's infrastructure includes Botshield LTD (UK-registered, AS213613), which provides DDoS mitigation services while simultaneously operating the botnet — a brazen dual-use model. The FBI has seized multiple domains associated with Forky's operations (stresser.best, stresser.us) across Operation PowerOFF enforcement waves.

The evolution from Mirai's 1 Tbps record in 2016 to Aisuru's 31.4 Tbps in 2025 represents a 31x increase in peak DDoS capacity in under a decade. Hyper-volumetric attacks grew 700% in 2025, with most lasting under 35-45 seconds — too fast for human intervention or on-demand scrubbing services to activate.

## MITRE ATT&CK

- T1583.005 Botnet
- T1190 Exploit Public-Facing Application
- T1195.003 Compromise Hardware Supply Chain
- T1059.004 Unix Shell
- T1547 Boot or Logon Autostart Execution
- T1027.013 Encrypted/Encoded File
- T1110.001 Password Guessing
- T1046 Network Service Discovery
- T1210 Exploitation of Remote Services
- T1119 Automated Collection
- T1071.001 Web Protocols
- T1090.003 Multi-hop Proxy
- T1573.001 Symmetric Cryptography
- T1568.002 Domain Generation Algorithms
- T1498.001 Direct Network Flood
- T1498.002 Reflection Amplification
- T1499 Endpoint Denial of Service
- T1489 Service Stop
- T1595.001 Scanning IP Blocks
- T1584.005 Botnet
- T1070.005 Network Share Connection Removal
- T1053.003 Cron
- T1485 Data Destruction
- T1571 Non-Standard Port

## Sources

- [Cloudflare 2025 Q4 DDoS Threat Report — 31.4 Tbps Record](https://blog.cloudflare.com/ddos-threat-report-2025-q4/)
- [Cloudflare 2025 Q3 DDoS Threat Report — Aisuru, the Apex of Botnets](https://blog.cloudflare.com/ddos-threat-report-2025-q3/)
- [Cloudflare Blocks Monumental 7.3 Tbps DDoS Attack](https://blog.cloudflare.com/defending-the-internet-how-cloudflare-blocked-a-monumental-7-3-tbps-ddos/)
- [Cloudflare 2025 Q2 DDoS Threat Report](https://blog.cloudflare.com/ddos-threat-report-for-2025-q2/)
- [Cloudflare 2025 Q1 DDoS Threat Report — 20.5M Attacks](https://blog.cloudflare.com/ddos-threat-report-for-2025-q1/)
- [KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS — Aisuru Attribution](https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with-near-record-6-3-tbps-ddos/)
- [QiAnXin XLab — Botnets Never Die: Analysis of AIRASHI](https://blog.xlab.qianxin.com/large-scale-botnet-airashi-en/)
- [Wired — Eleven11bot Record-Size DDoS (6.5 Tbps, Mirai Variant)](https://www.wired.com/story/eleven11bot-botnet-record-size-ddos-attacks/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0098
