Skip to content

Aisuru

Aisuru is an IoT-focused DDoS botnet associated with very large-scale volumetric attacks and with the broader Keksec ecosystem.

Profile source: Mallory opens in a new tab

Aisuru

Family profile

Aisuru is an IoT-focused DDoS botnet associated with very large-scale volumetric attacks and with the broader Keksec ecosystem. It has been cited alongside Mirai-derived botnet activity and has been linked through shared tooling or infrastructure to related operations such as Kaitori and to the KimWolf variant. Public reporting has tied Aisuru to record-setting attacks in the tens of terabits per second and to a botnet population measured in the millions of compromised devices.

The botnet is used primarily for distributed denial-of-service operations and has also been described as supporting cybercrime-as-a-service and residential proxy abuse. Reported victim device classes include internet-connected and embedded systems typical of IoT botnets, and related activity has included automated internet-wide scanning for exposed services and enrollment of devices using weak or default credentials. KimWolf, described by authorities as a variant of Aisuru, primarily targeted Android devices exposed through Android Debug Bridge, indicating that the broader Aisuru ecosystem has included Android as well as general IoT targets.

Aisuru has figured prominently in multinational law-enforcement disruption efforts. Authorities in the United States, Germany, and Canada seized command-and-control infrastructure associated with Aisuru and related botnets including KimWolf, JackSkid, and Mossad in 2026. The botnet is notable for its scale, its role in record-breaking DDoS campaigns, and its place within a cluster of parallel IoT botnet operations tied to the Keksec ecosystem.

Capabilities

  • Brute Force
  • Ddos
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 3, 2026
Last activity
Aug 9, 2026
Feed role
C2
Host form
22 IP / 0 hostnames

Leading locations

  • SG7
  • US5
  • DE4
  • HK2
  • MD2
  • CN1
  • NL1

Leading providers

  • DigitalOcean, LLC14
  • ALEXHOST SRL3
  • ADCDATA.COM1
  • FranTech Solutions1
  • Hangzhou Alibaba Advertising Co.,Ltd.1
  • LUCIDACLOUD LIMITED1

Infrastructure traits

  • Hosting 22
  • Proxy 1

Reported operators

Threat actors

2 named in public reporting
Keksec

Shared infrastructure ties the operator to the Keksec ecosystem, home to Kaitori and AISURU tooling.

Kimwolf

Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.

MITRE ATT&CK

Aisuru in ATT&CK

30 distinct techniques

Reporting

Research mentioning Aisuru

Jul 21
Security Online Info

TuxBot v3 Evolution: LLM-Built IoT Botnet Exposed

Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnetโ€™s source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malwareโ€™s working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.

Jul 16
Scworld

New TuxBot v3 Evolution IoT botnet framework shows signs of AI development | brief | SC Media

Jul 16
Security Affairs

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

Jul 16
Cyber Security News

New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

Jul 16
Cysecurity News

AI-Assisted TuxBot v3 Evolution Botnet Targets IoT Devices With Modular Multi-Channel Attack Framework - CySecurity News - Latest Information Security and Hacking Incidents

Jul 15
The Hacker News

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Jul 15
Palo Alto Networks Unit 42

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.