Researchers and network defenders linked the Aisuru botnet to a wave of hyper-volumetric distributed denial-of-service attacks that pushed internet-scale flooding to new highs. Reports described attacks reaching 11.5 Tbps and later 22.2 Tbps with 10.6 billion packets per second, with one major incident lasting about 40 seconds and being automatically mitigated by Cloudflare. Coverage from Cloudflare, The Register, Cybersecurity Dive, and QiAnXin XLab said the botnet helped fuel a broader rise in DDoS activity and turned parts of the internet into what one report characterized as a terabit-scale stress test.
Government and industry tracking indicated the botnet was not an isolated spike but an active threat affecting organizations across regions, including the UK. Germany's BSI published an Aisuru botnet profile as defenders continued cataloging its infrastructure and behavior, while media reports said British businesses were hit by record botnet-driven barrages. Across the referenced reporting, Aisuru emerged as a large-scale botnet associated with compromised devices and capable of launching short, extremely intense floods that set new benchmarks for DDoS volume and forced providers to rely on automated mitigation at massive scale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-11, Germany's Federal Office for Information Security (BSI) published an Aisuru botnet profile. The listing marked official government tracking and public documentation of the threat.
On 2026-02-06, reporting indicated British businesses were being battered by a record botnet-driven DDoS blitz associated with Aisuru. This reflected the botnet's continued operational impact beyond the initial record attacks.
On 2025-12-04, The Register reported on Aisuru as a botnet behind terabit-scale DDoS activity, emphasizing its role in unprecedented internet-scale attack traffic. The article largely reflected previously disclosed attack milestones rather than a separate incident.
On 2026-01-01, Cloudflare published a dedicated threat intelligence report on Aisuru, detailing how early October attacks escalated into record-setting DDoS activity. The report consolidated technical analysis and attribution around the botnet's operations.
On 2025-12-03, Cloudflare's Q3 DDoS findings were reported as showing rising attack volume, with Aisuru identified as a major driver of record attacks. The reporting connected the botnet to the surge in hyper-volumetric incidents.
In early October 2025, attacks associated with the Aisuru botnet intensified and escalated into record-setting DDoS activity. Later reporting tied this period to terabit-scale attacks and broader operational growth by the botnet.
By 2025-09-24, Cloudflare disclosed that it had autonomously mitigated a record-breaking DDoS attack peaking at 22.2 Tbps and 10.6 billion packets per second. The attack lasted about 40 seconds and was described as nearly twice as large as the previous record event.
On 2025-09-15, QiAnXin XLab published research describing Aisuru as an ultra-large botnet capable of 11.5 Tbps-scale attacks. The report provided early technical details about the botnet's scale and operations.
In early September 2025, Cloudflare mitigated a hyper-volumetric DDoS attack peaking at 11.5 Tbps, later attributed to the Aisuru botnet. The incident was described as one of the largest attacks observed at the time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
bsi.bund.de
Open sourcetheregister.com
Open sourcecloudflare.com
Open sourcetheregister.com
Open sourcecybersecuritydive.com
Open sourcepcgamer.com
Open sourceblog.xlab.qianxin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.