A March multinational operation involving the United States, Canada, and Germany disrupted infrastructure supporting the Aisiru and Kimwolf botnets, contributing to a fall in the largest observed botnet from 13.5 million devices in Q1 2026 to 2.09 million in Q2. Link11 also reported a 42% decline in DDoS attacks in Europe during the first half of 2026, partly attributing the reduction to law-enforcement actions including Operation Eastwood and the shutdown of four IoT botnets.
Attackers are compensating with more powerful and resilient campaigns: Link11 recorded peaks of 2.3 Tbit/s and 322 million packets per second, with 705 TB of cumulative malicious traffic, driven by super-botnets and hijacked cloud servers. Operators are increasingly dispersing traffic sources and adopting decentralized command infrastructure; the Aeternum and Void botnets use Polygon and Ethereum smart contracts for C2 distribution. DDoS surges are also being used to conceal SQL-injection and XSS probing, requiring defenses that combine continuous traffic inspection, behavioral detection, adaptive filtering, and application-layer monitoring.

Pull IOCs and campaign context straight into your stack.
12 events from the most recent confirmed update back to the earliest known activity.
Authorities in the United States, Canada, and Germany conducted a coordinated operation that disrupted command-and-control infrastructure for major IoT botnets. The sources identify Aisiru/Kimwolf infrastructure among the targets and report that four disrupted botnets collectively controlled more than three million devices.
In the second quarter of 2026, the top three countries accounted for 32% of application-layer DDoS sources and the top 20 accounted for 70%, down from 47% and about 76% respectively a year earlier. This reduced the effectiveness of country-based filtering as a standalone control.
The largest observed botnet declined to 2.09 million devices in the second quarter of 2026. The decline was assessed as likely influenced by the March multinational disruption, alongside possible remediation and device replacement activity.
During the first half of 2026, Link11 found that 56% of organizations hit by a DDoS attack experienced a second attack within 30 days, up from 46% a year earlier.
Link11 documented attackers using a DDoS traffic spike against two domains as cover for SQL-injection and cross-site-scripting probing. The attackers reused the same IP addresses for the volumetric traffic and the application-layer probes.
During the first half of 2026, Link11 recorded a 2.3 Tbit/s peak DDoS attack, 322 million packets per second, and 705 TB of cumulative attack traffic. It attributed the increased force in part to super-botnets and hijacked cloud servers, despite a 42% decline in attack counts.
The largest observed botnet reached 13.5 million devices during the first quarter of 2026, following rapid growth from prior years.
Operation Eastwood disrupted infrastructure used by the pro-Russian NoName057(16) group.
The largest observed botnet grew to 5.76 million compromised devices in 2025.
The largest observed botnet size increased to 228,000 devices in 2024.
The largest observed botnet size was 136,000 compromised devices in 2023.
Aeternum was identified as using Polygon smart contracts and Void as using Ethereum smart contracts for command-and-control instructions or infrastructure pointers. This decentralized approach reduces reliance on C2 servers that authorities can seize or take offline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcesecuritysenses.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.