Last seven days
- First activity
- Aug 3, 2026
- Last activity
- Aug 9, 2026
- Feed role
- C2
- Host form
- 22 IP / 0 hostnames
Aisuru is an IoT-focused DDoS botnet associated with very large-scale volumetric attacks and with the broader Keksec ecosystem.
Profile source: Mallory opens in a new tabAisuru
Aisuru is an IoT-focused DDoS botnet associated with very large-scale volumetric attacks and with the broader Keksec ecosystem. It has been cited alongside Mirai-derived botnet activity and has been linked through shared tooling or infrastructure to related operations such as Kaitori and to the KimWolf variant. Public reporting has tied Aisuru to record-setting attacks in the tens of terabits per second and to a botnet population measured in the millions of compromised devices.
The botnet is used primarily for distributed denial-of-service operations and has also been described as supporting cybercrime-as-a-service and residential proxy abuse. Reported victim device classes include internet-connected and embedded systems typical of IoT botnets, and related activity has included automated internet-wide scanning for exposed services and enrollment of devices using weak or default credentials. KimWolf, described by authorities as a variant of Aisuru, primarily targeted Android devices exposed through Android Debug Bridge, indicating that the broader Aisuru ecosystem has included Android as well as general IoT targets.
Aisuru has figured prominently in multinational law-enforcement disruption efforts. Authorities in the United States, Germany, and Canada seized command-and-control infrastructure associated with Aisuru and related botnets including KimWolf, JackSkid, and Mossad in 2026. The botnet is notable for its scale, its role in record-breaking DDoS campaigns, and its place within a cluster of parallel IoT botnet operations tied to the Keksec ecosystem.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Shared infrastructure ties the operator to the Keksec ecosystem, home to Kaitori and AISURU tooling.
Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.
MITRE ATT&CK
Reporting
Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnetโs source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malwareโs working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.