Aisuru is a Linux-based IoT botnet active since at least mid-2024 and primarily used for high-volume distributed denial-of-service operations. It compromises exposed internet-connected devices through Android Debug Bridge exposure, known vulnerabilities, and weak or default credentials. Aisuru-related samples have targeted operational-technology devices using embedded default credentials and include destructive directory-wiping functionality. The botnet has also evolved toward residential proxy functionality, allowing compromised devices to be used as proxy nodes. Following exposure in 2024, the AISURU development lineage produced the kitty and AIRASHI variants; these retained DDoS functionality while adding capabilities including proxying, encrypted command-and-control mechanisms, arbitrary command execution, and reverse-shell access. Aisuru has been associated with multi-terabit DDoS activity and is regarded as a super-botnet because of its attack capacity and large compromised-device base. Law-enforcement authorities disrupted infrastructure associated with Aisuru and related botnets in March 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
„Најраниот пронајден примерок, кој ја таргетира x86 архитектурата со експлоатација на Dirty COW , укажува дека оваа фамилија еволуирала од традиционална Linux експлоатација кон актуелниот Android модел на ширење базиран на ADB“
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shared infrastructure ties the operator to the Keksec ecosystem, home to Kaitori and AISURU tooling.
Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code.
The biggest change, according to the report, is a new flood method built on HTTP/2, the protocol that carries most web traffic today.
Потоа инсталира малициозен софтвер способен за изведување DDoS напади и за претворање на уредот во реле преку кое се пренасочува злонамерен сообраќај.
Tor resolves that address through its own network rather than the ordinary domain system, and it hides where the server actually sits, which leaves investigators without a host to contact.
generic malware, such as botnets, is increasingly targeting OT devices... exploit OT default credentials and wipe data directories
“The highest measured bandwidth attack reached 2.3 Tbit/s” and “Attackers are steering their botnets with greater precision and control, generating more traffic in less time.”
105 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
176 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A super-botnet cited as contributing to the increasing intensity of DDoS attacks against European organizations.
A super-botnet cited as contributing to record DDoS attack bandwidth, packet rates, and cumulative traffic against European organizations.
A botnet mentioned only as part of a separate law-enforcement disruption operation.
Aisuru is described as a botnet involved in DDoS operations, using C2 infrastructure and ADB exploitation, and evolving toward a proxy network/proxyware model.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.