Aisuru-Kimwolf is a botnet threat cluster associated with Mirai-derived distributed denial-of-service activity and linked to some of the largest volumetric attacks publicly reported, including attacks measured at 31.4 Tbps and 14.1 billion packets per second. The cluster is associated with the Aisuru and KimWolf botnets, both tied to the broader Mirai ecosystem, which has proliferated through extensive reuse and modification of leaked source code. The actor’s operations are centered on compromising insecure internet-connected devices and using them as part of a for-hire attack infrastructure. Reported tradecraft includes large-scale DDoS operations, packet randomization to evade defensive filtering and detection, and the use of residential proxy services to obscure operator activity and blend malicious traffic with legitimate residential networks. KimWolf has been specifically associated with targeting Android-based systems, including mobile devices and smart TVs. Following infrastructure disruption efforts, KimWolf operators reportedly shifted portions of their activity to I2P to reduce visibility and complicate takedown efforts. Aisuru-Kimwolf fits the profile of a financially motivated criminal botnet operation rather than a nation-state actor. It is part of a broader ecosystem of Mirai-derived services marketed to paying customers for attack-on-demand use. The botnets Aisuru and KimWolf have also been named in law-enforcement disruption actions alongside other botnet operations such as JackSkid and Mossad.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.