Skip to content
Malware family AndroidIot

Aisuru

AISURU is an Internet-of-Things botnet associated with large-scale distributed denial-of-service operations and a broader ecosystem of related malware and infrastructure.

Profile source: Mallory opens in a new tab

Aisuru

Family profile

AISURU is an Internet-of-Things botnet associated with large-scale distributed denial-of-service operations and a broader ecosystem of related malware and infrastructure. It has been cited alongside Mirai-derived and Keksec-linked botnet activity, and later law-enforcement actions grouped it with KimWolf, JackSkid, and Mossad as part of a cluster of high-impact IoT botnets. Reporting has also described KimWolf as a variant of AISURU, indicating code or operational lineage within the same botnet family.

The malware compromises internet-connected devices and enrolls them into a botnet used for volumetric DDoS attacks. Public reporting attributes record-setting attacks to AISURU, including multi-terabit events, and describes the botnet as having infected millions of devices at peak scale. Operational behavior associated with the AISURU ecosystem includes scanning for exposed services, exploiting weak or default credentials, and targeting exposed Android Debug Bridge on Android-based devices. Android and embedded IoT systems such as routers, cameras, DVRs, streaming devices, digital photo frames, and similar consumer or small-office hardware have been associated with this activity.

AISURU has also been linked to cybercrime-as-a-service operations in which botnet capacity was rented to other actors for DDoS attacks. Beyond denial-of-service activity, reporting has connected the broader AISURU-linked ecosystem to proxy enablement and abuse of compromised residential connectivity, although the core, consistently supported characterization of AISURU is as an IoT DDoS botnet. International disruption efforts in 2026 targeted command-and-control infrastructure associated with AISURU and related botnets, reflecting its significance as a major operational threat in the IoT botnet landscape.

Capabilities

  • Brute Force
  • Ddos
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 21, 2026
Feed role
C2
Host form
32 IP / 0 hostnames

Leading locations

  • SG14
  • GB8
  • DE5
  • US4
  • CA1

Leading providers

  • DigitalOcean, LLC24
  • The Constant Company, LLC7
  • Packet Star Networks Limited1

Infrastructure traits

  • Hosting 32
  • Vpn 1

Reported operators

Threat actors

2 named in public reporting
Keksec

Researchers traced the botnet's origins to code borrowed from multiple malware families, including Mirai, AISURU, and Wuhan...

Kimwolf

Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.

MITRE ATT&CK

Aisuru in ATT&CK

30 distinct techniques

Reporting

Research mentioning Aisuru

Jul 16
Scworld

New TuxBot v3 Evolution IoT botnet framework shows signs of AI development | brief | SC Media

Tracing its lineage to botnets like Mirai and AISURU, TuxBot v3 Evolution also incorporates code from the MHDDoS Python toolkit.

Jul 16
Security Affairs

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

Shared dropper infrastructure at 185.10.68[.]127 on FlokiNET links TuxBot to Kaitori v3.9 and AISURU tooling... placing the operator within the Keksec ecosystem.

Jul 16
Cysecurity News

AI-Assisted TuxBot v3 Evolution Botnet Targets IoT Devices With Modular Multi-Channel Attack Framework - CySecurity News - Latest Information Security and Hacking Incidents

Researchers traced the botnet's origins to code borrowed from multiple malware families, including Mirai, AISURU, and Wuhan...

Jul 15
The Hacker News

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

The modular framework's lineage has been traced back to three different botnets, like Mirai, AISURU, and Wuhan...

Jul 15
Palo Alto Networks Unit 42

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

Based on our analysis of the samples, TuxBot includes features borrowed from the known botnet AISURU.

Jun 30
The Hacker News

RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

AISURU and a cluster of related botnets, more than three million hijacked devices between them, drove attacks near 30 Tbps before a US-led operation tore down their infrastructure this spring.

Jun 27
Codeby

Защита от DDoS атак: anycast, scrubbing и автоматизация

По данным Terrazone, ботнеты уровня Aisuru в 2025 году насчитывали от 1 до 4 миллионов заражённых устройств...

Jun 22
Osint Team

When Every Lamppost Can Think: The Security Problem the Octopus Model Ignores | by Berend Watchus | Jun, 2026 | OSINT Team

This isn’t hypothetical — it’s the entire history of IoT botnets, from Mirai in 2016 through the Aisuru and RondoDox campaigns still running in 2025–2026, which scan the internet for devices with default passwords and enroll them automatically.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.