AISURU is an Internet-of-Things botnet associated with large-scale distributed denial-of-service operations and a broader ecosystem of related malware and infrastructure. It has been cited alongside Mirai-derived and Keksec-linked botnet activity, and later law-enforcement actions grouped it with KimWolf, JackSkid, and Mossad as part of a cluster of high-impact IoT botnets. Reporting has also described KimWolf as a variant of AISURU, indicating code or operational lineage within the same botnet family.
The malware compromises internet-connected devices and enrolls them into a botnet used for volumetric DDoS attacks. Public reporting attributes record-setting attacks to AISURU, including multi-terabit events, and describes the botnet as having infected millions of devices at peak scale. Operational behavior associated with the AISURU ecosystem includes scanning for exposed services, exploiting weak or default credentials, and targeting exposed Android Debug Bridge on Android-based devices. Android and embedded IoT systems such as routers, cameras, DVRs, streaming devices, digital photo frames, and similar consumer or small-office hardware have been associated with this activity.
AISURU has also been linked to cybercrime-as-a-service operations in which botnet capacity was rented to other actors for DDoS attacks. Beyond denial-of-service activity, reporting has connected the broader AISURU-linked ecosystem to proxy enablement and abuse of compromised residential connectivity, although the core, consistently supported characterization of AISURU is as an IoT DDoS botnet. International disruption efforts in 2026 targeted command-and-control infrastructure associated with AISURU and related botnets, reflecting its significance as a major operational threat in the IoT botnet landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers traced the botnet's origins to code borrowed from multiple malware families, including Mirai, AISURU, and Wuhan...
Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers gained access to these devices either by exploiting known security flaws or by logging in with default factory credentials that most users never change.
Prime targets included Android TVs and streaming devices with exposed Android Debug Bridge (ADB) services.
Late 2025 brought faster turnover... Investigators later found that its 1.8 million bots were generated through exploitation of proxy services.
Like other TurboMirai botnets, Aisuru incorporates additional dedicated DDoS attack capabilities and multi-use functions, enabling operators to carry out other illicit activities, including credential stuffing, artificial intelligence (AI)-driven web scraping, spamming, and phishing.
This isn’t hypothetical — it’s the entire history of IoT botnets, from Mirai in 2016 through the Aisuru and RondoDox campaigns still running in 2025–2026, which scan the internet for devices with default passwords and enroll them automatically.
Beyond DDoS attacks, the botnets have been used to abuse residential proxy networks, routing attack traffic through IP addresses belonging to ordinary homeowners, making the activity far harder to trace.
The infected devices were enslaved by the botnet operators. The operators then used a “cybercrime as a service” model to sell access to the infected devices to other cyber criminals.
A DDoS attack tries to crowd an application, network, server, or website with traffic from various servers at one time. Few attacks are aimed at network capacity, while the remaining emphasize on application layer resources like APIs and login pages.
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
161 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a lineage/source influence for TuxBot v3 Evolution.
A separate tooling/codebase linked to TuxBot through shared infrastructure and associated with the Keksec ecosystem.
Referenced as a malware family whose code and tooling were partially reused by TuxBot; shared infrastructure also links TuxBot to AISURU tooling.
An IoT botnet/tooling family referenced as part of TuxBot's lineage; shared infrastructure and tooling also link TuxBot to the Keksec ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.