Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2
- Host form
- 32 IP / 0 hostnames
AISURU is an Internet-of-Things botnet associated with large-scale distributed denial-of-service operations and a broader ecosystem of related malware and infrastructure.
Profile source: Mallory opens in a new tabAisuru
AISURU is an Internet-of-Things botnet associated with large-scale distributed denial-of-service operations and a broader ecosystem of related malware and infrastructure. It has been cited alongside Mirai-derived and Keksec-linked botnet activity, and later law-enforcement actions grouped it with KimWolf, JackSkid, and Mossad as part of a cluster of high-impact IoT botnets. Reporting has also described KimWolf as a variant of AISURU, indicating code or operational lineage within the same botnet family.
The malware compromises internet-connected devices and enrolls them into a botnet used for volumetric DDoS attacks. Public reporting attributes record-setting attacks to AISURU, including multi-terabit events, and describes the botnet as having infected millions of devices at peak scale. Operational behavior associated with the AISURU ecosystem includes scanning for exposed services, exploiting weak or default credentials, and targeting exposed Android Debug Bridge on Android-based devices. Android and embedded IoT systems such as routers, cameras, DVRs, streaming devices, digital photo frames, and similar consumer or small-office hardware have been associated with this activity.
AISURU has also been linked to cybercrime-as-a-service operations in which botnet capacity was rented to other actors for DDoS attacks. Beyond denial-of-service activity, reporting has connected the broader AISURU-linked ecosystem to proxy enablement and abuse of compromised residential connectivity, although the core, consistently supported characterization of AISURU is as an IoT DDoS botnet. International disruption efforts in 2026 targeted command-and-control infrastructure associated with AISURU and related botnets, reflecting its significance as a major operational threat in the IoT botnet landscape.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Researchers traced the botnet's origins to code borrowed from multiple malware families, including Mirai, AISURU, and Wuhan...
Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.
MITRE ATT&CK
Reporting
Tracing its lineage to botnets like Mirai and AISURU, TuxBot v3 Evolution also incorporates code from the MHDDoS Python toolkit.
Shared dropper infrastructure at 185.10.68[.]127 on FlokiNET links TuxBot to Kaitori v3.9 and AISURU tooling... placing the operator within the Keksec ecosystem.
Researchers traced the botnet's origins to code borrowed from multiple malware families, including Mirai, AISURU, and Wuhan...
The modular framework's lineage has been traced back to three different botnets, like Mirai, AISURU, and Wuhan...
Based on our analysis of the samples, TuxBot includes features borrowed from the known botnet AISURU.
AISURU and a cluster of related botnets, more than three million hijacked devices between them, drove attacks near 30 Tbps before a US-led operation tore down their infrastructure this spring.
По данным Terrazone, ботнеты уровня Aisuru в 2025 году насчитывали от 1 до 4 миллионов заражённых устройств...
This isn’t hypothetical — it’s the entire history of IoT botnets, from Mirai in 2016 through the Aisuru and RondoDox campaigns still running in 2025–2026, which scan the internet for devices with default passwords and enroll them automatically.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.