AIRASHI is a DDoS-focused botnet malware family assessed as an evolved variant of AISURU, following an intermediate variant referred to as kitty. It emerged in late 2024 and has been associated with large-scale distributed denial-of-service operations, including attacks timed for maximum disruption and sustained terabit-scale attack capacity. Reported operations have targeted victims globally across multiple industries, with no strong sector-specific bias, and have included attacks against gaming-related infrastructure during a major game release period.
AIRASHI primarily spreads by exploiting exposed devices through a mix of known vulnerabilities, weak Telnet credentials, and at least one actively exploited zero-day affecting Cambium Networks cnPilot routers. Reported exploitation activity also spans routers, cameras, DVR/NVR appliances, GPON equipment, and Android Debug Bridge-exposed systems, indicating a broad focus on internet-facing embedded and edge devices suitable for botnet recruitment.
Technically, AIRASHI incorporates multiple components and variants, including a DDoS-capable implant and proxy-oriented tooling. Observed AIRASHI-DDoS functionality includes command execution, reverse shell access, heartbeat and control messaging, and attack orchestration. Related variants include a Go-based proxy component and a modified proxy-focused branch derived from the AIRASHI codebase. The family has also used resilient command-and-control discovery methods, including DNS-based retrieval, and newer protocol designs employing RC4-obfuscated strings together with HMAC-SHA256 and ChaCha20 for protected communications.
The malware has been linked to operators who maintain distributed command-and-control infrastructure and publicly advertise attack performance. Overall, AIRASHI is best characterized as a rapidly iterated botnet centered on high-volume DDoS operations, with additional proxy and remote-command capabilities that support post-compromise control of infected devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
AIRASHI 使用的漏洞如下: ... cve_2017_5259 ... | 本文将要分析的正是 AISURU 僵尸网络的变种版本 AIRASHI 。… 当前AIRASHI僵尸网络主要有以下几个特点: 使用美国Cambium Networks公司的cnPilot路由器0DAY漏洞传播样本… 稳定的T级别DDoS攻击能力
AIRASHI 使用的漏洞如下: ... cve_2020_25499 ... | 本文将要分析的正是 AISURU 僵尸网络的变种版本 AIRASHI 。… 当前AIRASHI僵尸网络主要有以下几个特点: 使用美国Cambium Networks公司的cnPilot路由器0DAY漏洞传播样本… 稳定的T级别DDoS攻击能力
Table 1 — The vulnerabilities exploited by AIRASHI. | The following analysis will focus on the new variants, kitty and AIRASHI... The current AIRASHI botnet has the following main characteristics: Uses a zero-day (0day) vulnerability of cnPilot routers to spread samples.
AIRASHI 使用的漏洞如下: ... cve_2016_20016 ... | 本文将要分析的正是 AISURU 僵尸网络的变种版本 AIRASHI 。… 当前AIRASHI僵尸网络主要有以下几个特点: 使用美国Cambium Networks公司的cnPilot路由器0DAY漏洞传播样本… 稳定的T级别DDoS攻击能力
AIRASHI 使用的漏洞如下: ... cve_2020_8515 ... | 本文将要分析的正是 AISURU 僵尸网络的变种版本 AIRASHI 。… 当前AIRASHI僵尸网络主要有以下几个特点: 使用美国Cambium Networks公司的cnPilot路由器0DAY漏洞传播样本… 稳定的T级别DDoS攻击能力
Table 1 — The vulnerabilities exploited by AIRASHI. | The following analysis will focus on the new variants, kitty and AIRASHI... The current AIRASHI botnet has the following main characteristics: Uses a zero-day (0day) vulnerability of cnPilot routers to spread samples.
AIRASHI 使用的漏洞如下: ... cve_2023_28771 ... | 本文将要分析的正是 AISURU 僵尸网络的变种版本 AIRASHI 。… 当前AIRASHI僵尸网络主要有以下几个特点: 使用美国Cambium Networks公司的cnPilot路由器0DAY漏洞传播样本… 稳定的T级别DDoS攻击能力
0x1: RC4解密字符串解密 ... 3 'cve-2021-36260.ru' 4 'honeybooterz.cve-2021-36260.ru' | 本文将要分析的正是 AISURU 僵尸网络的变种版本 AIRASHI 。… 当前AIRASHI僵尸网络主要有以下几个特点: 使用美国Cambium Networks公司的cnPilot路由器0DAY漏洞传播样本… 稳定的T级别DDoS攻击能力
Table 1 — The vulnerabilities exploited by AIRASHI. | The following analysis will focus on the new variants, kitty and AIRASHI... The current AIRASHI botnet has the following main characteristics: Uses a zero-day (0day) vulnerability of cnPilot routers to spread samples.
Table 1 — The vulnerabilities exploited by AIRASHI. | The following analysis will focus on the new variants, kitty and AIRASHI... The current AIRASHI botnet has the following main characteristics: Uses a zero-day (0day) vulnerability of cnPilot routers to spread samples.
AIRASHI 使用的漏洞如下: ... CVE-2022-3573 cnPilot 0DAY ... | 本文将要分析的正是 AISURU 僵尸网络的变种版本 AIRASHI 。… 当前AIRASHI僵尸网络主要有以下几个特点: 使用美国Cambium Networks公司的cnPilot路由器0DAY漏洞传播样本… 稳定的T级别DDoS攻击能力
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The latest sample uses a SOCKS5 proxy (with authentication) to access the C2 server.
“AIRASHI uses three different methods to get C2… using DNS servers to resolve the C2's A record… Retrieves the C2's TXT record… Uses DNS servers to retrieve the C2's TXT record, then base64-decrypts and decrypts… using ChaCha20.”
92 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet variant (described as a variant of AISURU) deployed via cnPilot router zero-day exploitation to conduct DDoS attacks.
AIRASHI is a variant of the AISURU botnet, deployed via exploitation of router vulnerabilities to conduct DDoS attacks.
A DDoS botnet evolved from AISURU that also supports arbitrary command execution, reverse shell access, and proxy functionality. It uses RC4 for string decryption, HMAC-SHA256 and ChaCha20 in C2 communications, multiple DNS-based C2 retrieval methods, and exploits multiple N-day flaws plus a cnPilot router zero-day for propagation.
IoT-focused botnet used for large-scale DDoS attacks (reported stable 1–3 Tbps peaks) and, in some variants, proxying and remote command execution/reverse shell. It spreads via N-day vulnerabilities, TELNET weak passwords, and a reported cnPilot router 0-day. Newer variants use RC4 for string encryption and a C2 protocol with HMAC-SHA256 integrity and ChaCha20 encryption; C2 discovery includes DNS A/TXT record techniques with TXT-based ChaCha20 decoding in later samples.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.