Researchers linked the AIRASHI botnet to large-scale distributed denial-of-service attacks against Steam and Perfect World during the release period of Black Myth: Wukong, describing a Mirai-derived operation that evolved from AISURU and kitty into a globally distributed platform capable of sustained 1–3 Tbps floods. The operators allegedly showcased attack tests on Telegram, including a cited peak of 3.11 Tbps and 270.52 Mpps, while targeting organizations across multiple countries and sectors. AIRASHI was reported to use broad infection methods, including known vulnerabilities, Telnet weak passwords, and an actively exploited zero-day in Cambium Networks cnPilot routers.
Technical analysis showed the botnet had matured significantly, with RC4-obfuscated strings, DNS TXT-based command-and-control retrieval, and a newer C2 protocol using HMAC-SHA256 and ChaCha20. Researchers identified multiple malware families tied to the operation, including AIRASHI-DDoS, AIRASHI-Proxy, and Go-Proxisdk, with some variants supporting proxy functions and others focused on DDoS activity. The reporting also published infrastructure details such as C2 domains, downloader IPs, file hashes, and a Snort detection rule to help defenders identify exploitation attempts and infections tied to the cnPilot router compromise.

See which actors are running it and whether you're in range.
20 events from the most recent confirmed update back to the earliest known activity.
Steam, Riot Games, and PlayStation Network experienced major disruptions on October 6-7, 2025. The outages were real, but no official source confirmed they were caused by DDoS, and the widely shared 29.69 Tbps claim remained unverified.
Cloudflare confirmed a 22.2 Tbps DDoS attack on a European network infrastructure company that peaked at 10.6 billion packets per second and lasted about 40 seconds. Cloudflare and XLab assessed Aisuru was likely involved, though attribution was not definitive.
Cloudflare confirmed an 11.5 Tbps DDoS attack in early September 2025 against an undisclosed customer, and XLab definitively attributed that attack to the Aisuru botnet.
The Aisuru botnet reportedly grew sharply after a Totolink router firmware supply-chain compromise involving the update domain updatetoto[.]tw and a malicious script named t.sh. The assessment says the botnet expanded from fewer than 100,000 nodes to more than 300,000 after this event.
The botnet operators allegedly posted a DDoS capability test result on Telegram showing a peak of 3.11 Tbps and 270.52 Mpps.
XLab reported first observing the AIRASHI-Proxy sample class in early December 2024 as a modified AIRASHI codebase implementing proxy functionality with a private protocol.
XLab first observed the Go-Proxisdk sample family in late November 2024 and described it as a Go-based proxy tool built on muxado.
A new botnet variant appeared in late November 2024 and was renamed AIRASHI, continuing the AISURU lineage under a new identity.
By late October 2024, kitty had shifted to using SOCKS5 proxies for command-and-control communications and embedded large proxy and C2 lists in its string table.
XLab reported first seeing the AIRASHI-DDoS sample class in late October 2024. This family supported DDoS attacks, arbitrary command execution, and reverse shell functionality.
The AISURU botnet resurfaced in October 2024 as a new variant named kitty, which began spreading in early October.
After the August 2024 incident was exposed, the AISURU botnet temporarily ceased activity in September 2024.
XLab observed a planned large-scale DDoS campaign in August 2024 targeting Steam and Perfect World during the release period of Black Myth: Wukong. The attacks hit hundreds of servers across 13 global regions in multiple waves timed for peak gaming activity.
Researchers said they contacted Cambium Networks in June 2024 regarding the cnPilot router zero-day but received no response.
XLab reported that the botnet operators had been exploiting an undisclosed zero-day vulnerability in Cambium Networks cnPilot routers since June 2024 to spread infections.
LILIN released updated firmware version 2.0b60_20200207 to remediate the DVR vulnerabilities, including hostname validation and fixes for the arbitrary file-read issue.
360Netlab provided LILIN with proof-of-concept details for the in-the-wild FTP and NTP vulnerability paths used in exploitation.
LILIN responded to 360Netlab after a second outreach attempt concerning the DVR zero-day issues affecting its devices.
360Netlab contacted LILIN regarding the in-the-wild DVR zero-day vulnerabilities and initially received no response from the vendor.
360Netlab observed multiple attacker groups exploiting a LILIN DVR zero-day vulnerability chain to distribute IoT botnets, including Chalubo, FBot, and Moobot. The activity marked a shift from common N-day exploitation to active use of a 0-day for propagation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 71 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
gist.github.com
Open sourceblog.apnic.net
Open sourceblog.xlab.qianxin.com
Open sourceblog.netlab.360.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.