Cloudflare reported mitigating a record-breaking hyper-volumetric DDoS campaign attributed to the Aisuru/Kimwolf botnet, with a peak of 31.4 Tbps and application-layer floods exceeding 200 million HTTP requests per second. Cloudflare said the activity—named “The Night Before Christmas” due to its timing—began on December 19, 2025 and targeted both Cloudflare customers and Cloudflare’s own dashboard/infrastructure, with many victims described as telecommunications providers and IT organizations.
Reporting on Cloudflare’s findings indicates the campaign consisted of thousands of individual attacks that were typically short in duration (often 1–2 minutes), with the majority peaking in the 1–5 Tbps range and 1–5 billion packets per second. The botnet was also linked to prior record-setting activity (including a previously disclosed 29.7 Tbps peak), and Cloudflare attributed the attack sources in this campaign primarily to compromised Android TV/streaming devices; Cloudflare stated the attacks were automatically detected and mitigated without triggering internal alerts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On January 29, 2026, multiple outlets reported Cloudflare's disclosure of the December Aisuru/Kimwolf campaign, including details that the botnet relied heavily on compromised Android TV and other consumer devices.
Cloudflare's year-end reporting said it mitigated 47.1 million DDoS attacks in 2025, a 121% increase over 2024, with continued growth in Q4 and sharp increases in terabit-scale and high packet-rate attacks.
During the December 19 campaign, Cloudflare mitigated a publicly disclosed record DDoS event peaking at 31.4 Tbps and more than 200 million HTTP requests per second, attributing it to the Aisuru/Kimwolf botnet and saying mitigation was fully automated.
Beginning on December 19, 2025, the Aisuru/Kimwolf botnet launched a hyper-volumetric DDoS campaign targeting Cloudflare customers, Cloudflare infrastructure, and its dashboard, with attacks delivered in short, intense bursts.
In its 2025 Q3 DDoS threat reporting, cited by ZDNET, Cloudflare characterized Aisuru as the 'apex of botnets' and noted its frequent targeting of telecommunications, gaming, hosting, ISP, and financial services organizations.
Barracuda reported Kimwolf as active since 2025, portraying it as a stealthy botnet that embeds in enterprise and public-sector environments and uses dynamic communications to evade detection.
Barracuda described Aisuru as active since 2024, using automated scanning and exploitation to rapidly compromise vulnerable IoT devices and build a botnet capable of large volumetric DDoS attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcetomshardware.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceblog.barracuda.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.