Bitsight TRACE observed the Aisuru botnet issue 66,596 DDoS commands from 82 command-and-control servers against 10,234 victim IP addresses between February and June 2026. The attacks were predominantly short, direct volumetric floods, with UDP comprising roughly 55% of commands and TCP about 44%. A coordinated U.S., German, and Canadian law-enforcement operation disrupted the botnet on March 19, cutting observed daily attacks from 1,559 to 521 and producing a roughly three-week operational blackout before activity resumed at a lower level.
After the disruption, Aisuru operators consolidated their C2 infrastructure and shifted toward locally scanning for exposed Android Debug Bridge (ADB) services to install Android proxyware. Shared infrastructure, payloads, and C2 characteristics link Aisuru to the Kimwolf botnet, suggesting the operators are building a residential proxy network that could support internal reconnaissance and lateral movement in addition to the botnet's DDoS capability.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Bitsight TRACE observed Kimwolf conducting the same local scanning and payload-delivery activity through backconnect server 51.75.119[.]51. The shared infrastructure and behavior provided evidence connecting Kimwolf and Aisuru.
Kimwolf had been scanning local networks since at least this date, establishing that the local Android Debug Bridge scanning activity was sustained rather than a one-off operation.
Aisuru operators used proxy functionality to scan local addresses and ports associated with Android Debug Bridge, including 127.0.0.1:5555. The exploitation chain downloaded and installed an APK that deployed an ELF proxy bot capable of relaying TCP and UDP traffic.
Aisuru resumed activity after approximately three weeks without observed commands following the infrastructure seizure. Its post-takedown average was 521 commands per day, down from 1,559 per day before the disruption.
The U.S. Department of Justice, German, and Canadian authorities seized Aisuru C2 infrastructure and infrastructure associated with three sibling botnets. Observed Aisuru commands fell from 686 to zero overnight; its DNS dead-drop domain also went dark around the takedown.
Bitsight TRACE recorded Aisuru's highest daily volume during its February-to-June observation period, with 3,131 DDoS attack commands originating from its C2 infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcebitsight.com
Open sourceblog.xlab.qianxin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.