Aisuru/Kimwolf is a large-scale distributed denial-of-service botnet family associated with record-setting volumetric attacks. It has been linked to attacks reaching tens of terabits per second and extremely high packet rates, placing it among the most powerful publicly reported DDoS botnets. Reporting describes Aisuru and the combined Aisuru/Kimwolf ecosystem as having compromised roughly 1 to 4 million hosts globally.
Aisuru is used to launch large-scale DDoS attacks and includes features intended to complicate mitigation, including randomization of packet characteristics. Its command-and-control design has been described as using DNS TXT records to distribute controller address information. Kimwolf is described as an Android-focused subvariant or branch of Aisuru that adapts Aisuru’s DDoS functionality for Android devices, including smart TVs and mobile devices. Kimwolf alone has been reported to have compromised about 2 million Android-based devices.
The botnet’s operators have been described as monetizing access to compromised devices and attack capability through online channels, including messaging platforms, and as using intermediary proxy infrastructure to obscure operations. Public reporting also notes law-enforcement disruption activity targeting infrastructure associated with Aisuru, Kimwolf, JackSkid, and Mossad in 2026, including action against command-and-control systems across multiple countries.
Aisuru/Kimwolf primarily targets internet-connected and consumer edge devices at scale to build attack capacity, with Kimwolf specifically focused on Android-based systems. The botnet is notable for both its scale and its operational role in the contemporary DDoS-for-hire and illicit attack-services ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Spamhaus noted that July to December 2025 saw a 24% increase in the number of botnet command & control servers identified... law enforcement attempted to take down Command and Control infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DDoS botnet mentioned only for comparison of attack capacity.
Large-scale botnet family used for record-setting DDoS attacks. It can randomize packet characteristics to hinder detection, encodes C2 IPs in DNS TXT records, and has been monetized by selling access to compromised devices to other cybercriminals.
Large-scale DDoS botnet ecosystem (including Android variant Kimwolf) attributed to hyper-volumetric HTTP DDoS activity; also monetized via proxy bandwidth and other services (per excerpted headlines).
A large-scale HTTP/network-layer DDoS botnet reported to have compromised over 2 million Android devices (notably off-brand Android TVs) and used to launch hyper-volumetric DDoS attacks, including a 31.4 Tbps event and the campaign dubbed 'The Night Before Christmas.'
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.