Microsoft Azure was targeted by a massive Distributed Denial of Service (DDoS) attack peaking at 15.72 terabits per second (Tbps) and nearly 3.64 billion packets per second (Bpps), making it the largest cloud DDoS attack ever recorded. The attack, which occurred on October 24, 2025, was launched from over 500,000 IP addresses and targeted a single public endpoint in Australia. The Aisuru botnet, a Turbo Mirai-class IoT botnet, was responsible for the attack, leveraging compromised home routers, cameras, and other IoT devices, primarily from residential ISPs in the United States and other countries. Azure’s global DDoS protection network successfully detected and mitigated the attack, ensuring service continuity.
The Aisuru botnet has rapidly grown in scale, reportedly ballooning in April 2025 after breaching a TotoLink router firmware update server and infecting approximately 100,000 devices. The botnet exploits vulnerabilities in a range of devices, including IP cameras, DVRs/NVRs, and routers from vendors such as T-Mobile, Zyxel, D-Link, and Linksys. Security researchers and Microsoft have highlighted the increasing threat posed by such IoT-based botnets, as faster home internet connections and more powerful devices enable attackers to launch ever-larger DDoS attacks. The incident underscores the need for robust DDoS protection for all internet-facing applications and workloads, especially as attack sizes continue to escalate.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly reported that it successfully mitigated the record-breaking Azure DDoS attack and shared key technical details about its scale, packet rate, and botnet attribution. Multiple outlets covered the same disclosure as the public revelation of the incident.
Microsoft Azure was targeted by a massive distributed denial-of-service attack attributed to the AISURU botnet, reaching roughly 15.7 Tbps and about 3.64 billion packets per second. Reports say the attack traffic came from approximately 500,000 IP addresses, making it the largest cloud DDoS event publicly reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcethehackernews.com
Open sourcetechrepublic.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.