Skip to content
Data by Hatching Triage opens in a new tab AndroidIotLinuxNetwork Device

Aisuru

Aisuru is a Linux-based IoT botnet primarily used for high-volume, direct volumetric distributed denial-of-service attacks.

Profile source: Mallory opens in a new tab

Aisuru

Family profile

Aisuru is a Linux-based IoT botnet primarily used for high-volume, direct volumetric distributed denial-of-service attacks. Active since at least mid-2024, it has been associated with UDP and TCP flooding, typically issued as short commands that can be chained into sustained attack sessions. It has targeted organizations in the technology, finance, education, and government sectors globally.

Aisuru compromises exposed IoT and network-connected devices through known vulnerabilities, weak Telnet credentials, and Android Debug Bridge exposure. Historical samples include scanners and default credentials targeting operational-technology devices and contain destructive directory-wiping functionality. More recent activity used local scanning for Android Debug Bridge services to deploy an Android payload that converts compromised devices into TCP/UDP proxy relays.

The botnet uses encrypted command-and-control communications and resilient infrastructure-discovery mechanisms, including DNS TXT-record dead drops. It includes a backconnect proxy capability and has evolved toward operating a residential proxy network alongside DDoS operations. Shared infrastructure, payload behavior, command-and-control characteristics, and local Android Debug Bridge scanning link Aisuru activity to Kimwolf. Aisuru is also associated with the development lineage of kitty and AIRASHI variants. Infrastructure and tooling overlap have been reported with the Keksec ecosystem, although a definitive operator attribution is not established. Multinational law-enforcement action disrupted Aisuru command-and-control infrastructure in March 2026, after which activity resumed at a reduced level.

Capabilities

  • Brute Force
  • Ddos
  • Initial Access
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 18, 2026
Last activity
Sep 24, 2026
Feed role
C2 / Distribution
Host form
21 IP / 0 hostnames

Leading locations

  • GB8
  • DE4
  • US3
  • NL2
  • ID1
  • KR1
  • SE1
  • SG1

Leading providers

  • DigitalOcean, LLC14
  • Tencent Building, Kejizhongyi Avenue4
  • LIGHTBYTE LTD1
  • Storm Industries LLC1
  • SWISSNET LLC1

Infrastructure traits

  • Hosting 21

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Keksec

Shared infrastructure ties the operator to the Keksec ecosystem, home to Kaitori and AISURU tooling.

Kimwolf

Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.

Exploited software

Vulnerabilities linked to Aisuru

1 CVEs

MITRE ATT&CK

Aisuru in ATT&CK

39 distinct techniques

Reporting

Research mentioning Aisuru

Sep 4
Itpro

‘Attackers are steering their botnets with greater precision and control’: DDoS attack numbers might be dwindling, but they’re intensifying | IT Pro

A March multinational operation involving the United States, Canada, and Germany disrupted infrastructure supporting the Aisiru and Kimwolf botnets, contributing to a fall in the largest observed botnet from 13.5 million devices in Q1 2026 to 2.09 million in Q2. Link11 also reported a 42% decline in DDoS attacks in Europe during the first half of 2026, partly attributing the reduction to law-enforcement actions including Operation Eastwood and the shutdown of four IoT botnets. Attackers are compensating with more powerful and resilient campaigns: Link11 recorded peaks of 2.3 Tbit/s and 322 million packets per second, with 705 TB of cumulative malicious traffic, driven by super-botnets and hijacked cloud servers. Operators are increasingly dispersing traffic sources and adopting decentralized command infrastructure; the Aeternum and Void botnets use Polygon and Ethereum smart contracts for C2 distribution. DDoS surges are also being used to conceal SQL-injection and XSS probing, requiring defenses that combine continuous traffic inspection, behavioral detection, adaptive filtering, and application-layer monitoring.

Sep 4
Cyber Security News

Botnet Takedowns Are Working - But DDoS Operators Are Already Adapting

Sep 4
Cryptika

Botnet Takedowns Are Working - But DDoS Operators Are Already Adapting | Cryptika Cybersecurity

Sep 3
Securitysenses

Fewer attacks, more force: Link11's European Cyber Report finds new DDoS records for the first half of 2026 | SecuritySenses

Sep 2
Help Net Security

Global sinkhole operation ends Sality botnet’s 23-year run - Help Net Security

U.S., Bulgarian, Hungarian, and Romanian authorities, supported by CrowdStrike and the Shadowserver Foundation, disrupted the long-running Sality peer-to-peer botnet by seizing payload-hosting domains, dismantling control infrastructure, and sinkholing its super-peer network. The operation exploited Sality's unauthenticated peer-list protocol to redirect infected hosts away from operator-controlled infrastructure, cutting off delivery of new malware payloads and removing the botnet from the operators' control. Active since at least 2003, Sality infected more than 15,000 devices and spread by infecting Windows executables. CrowdStrike attributes the operation to SALTY SPIDER, a criminal group likely based in Russia's Republic of Bashkortostan; its infrastructure supported credential theft, spam, proxying, network exploitation, DDoS activity, and EggJagger cryptocurrency clipboard hijacking. Organizations should investigate UDP communications with 188.166.101[.]148, an indicator of Sality infection, because sinkholing prevents new payload delivery but does not remove malware from already compromised systems.

Sep 2
Mkd Cirt

Инфраструктурата на ботнетот Sality демонтирана во глобална координирана акција | MKD-CIRT | Национален центар за одговор на компјутерски инциденти

Sep 2
Security Week

23-Year-Old Sality P2P Botnet Disrupted - SecurityWeek

Sep 2
Malware News

Global public-private operation disrupts Sality botnet active for two decades - Malware News - Malware Analysis, News and Indicators

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.