AISURU is a Mirai-class IoT botnet and botnet-for-hire operation associated with large-scale distributed denial-of-service activity and, in some reporting, residential proxy monetization. It emerged publicly in 2024 and became widely known in 2025 for hyper-volumetric attacks that set or approached public DDoS records, including campaigns measured above 29 Tbps and later above 31 Tbps when activity was attributed to AISURU alone or jointly to AISURU and Kimwolf. The operation has been linked to attacks against gaming, hosting, telecommunications, and cloud-related targets, with gaming platforms repeatedly cited as a favored sector. AISURU is commonly referred to as a botnet, but the available reporting also supports describing it as the operator group behind that botnet and its associated DDoS-for-hire service. Known aliases and closely associated names include Aisuru, AISURU botnet, AISURU/Kimwolf, and in some reporting Kimwolf as an Android-focused variant or closely related splinter. Reporting also places AISURU-related activity alongside JackSkid and Mossad in the same broader criminal ecosystem disrupted by law enforcement. Separate infrastructure analysis has linked AISURU tooling and hosting overlap to the Keksec ecosystem, including relationships with Kaitori-related activity, although shared infrastructure does not by itself prove identical malware codebases. The botnet primarily compromises internet-connected embedded devices, especially routers, digital video recorders, IP cameras, gateways, Wi-Fi access points, and other Linux-based IoT equipment. Some reporting also ties the broader AISURU/Kimwolf activity cluster to compromised Android-based streaming and television devices. AISURU has been described as infecting millions of devices globally, with estimates ranging from roughly one million to several million compromised hosts at peak visibility. Operationally, AISURU is characterized by DDoS-as-a-service behavior, enabling rented attack capacity for customers on cybercrime forums and related channels. Reported capabilities include high-volume Layer 3/4 flooding and application-layer attack traffic, with campaigns consisting of short, intense bursts as well as repeated attack waves. Some reporting also attributes credential stuffing and phishing activity to the operators, though AISURU is primarily known for DDoS operations. Later reporting indicates the operation or associated actors also explored renting infected devices as proxy infrastructure. Technically, AISURU is consistently described as derived from or related to the Mirai lineage, with some sources calling it a TurboMirai-class botnet. Malware lineage and code-reuse reporting indicate that AISURU itself later served as a source of borrowed functionality for other botnet frameworks, including TuxBot. Researchers have also noted overlap between AISURU-related tooling and other botnet families in the broader Keksec orbit. Geographically, infected devices have been observed worldwide. Some reporting highlights concentrations in Brazil, India, the United States, and Argentina for the AISURU/Kimwolf cluster, and at least one assessment suggests a Brazil nexus for an actor involved in AISURU activity. That attribution is not uniformly corroborated, so it should be treated cautiously. In March 2026, authorities in the United States, Canada, and Germany, with support from private-sector partners, disrupted command-and-control infrastructure associated with AISURU, Kimwolf, JackSkid, and Mossad. Public reporting states the operation seized domains and virtual servers used to control the botnets and affected a combined device population of more than three million compromised systems. No high-confidence public attribution to a nation-state has been established; AISURU is best characterized as a financially motivated cybercriminal botnet operation centered on DDoS-for-hire services and related abuse of compromised IoT infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infrastructure overlap with TuxBot through shared hosting and certificate artifacts; not stated to be the same malware/codebase.
Referenced as a malware/tooling lineage and shared infrastructure element associated with the TuxBot operator's ecosystem.
Referenced as one of the botnets whose lineage/tooling influenced TuxBot; also cited in shared tooling tied to the Keksec ecosystem.
A known IoT botnet lineage whose features and infrastructure are linked to TuxBot; tooling converges on shared infrastructure with TuxBot and Kaitori.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.