Last seven days
- First activity
- Sep 18, 2026
- Last activity
- Sep 24, 2026
- Feed role
- C2 / Distribution
- Host form
- 21 IP / 0 hostnames
Aisuru is a Linux-based IoT botnet primarily used for high-volume, direct volumetric distributed denial-of-service attacks.
Profile source: Mallory opens in a new tabAisuru
Aisuru is a Linux-based IoT botnet primarily used for high-volume, direct volumetric distributed denial-of-service attacks. Active since at least mid-2024, it has been associated with UDP and TCP flooding, typically issued as short commands that can be chained into sustained attack sessions. It has targeted organizations in the technology, finance, education, and government sectors globally.
Aisuru compromises exposed IoT and network-connected devices through known vulnerabilities, weak Telnet credentials, and Android Debug Bridge exposure. Historical samples include scanners and default credentials targeting operational-technology devices and contain destructive directory-wiping functionality. More recent activity used local scanning for Android Debug Bridge services to deploy an Android payload that converts compromised devices into TCP/UDP proxy relays.
The botnet uses encrypted command-and-control communications and resilient infrastructure-discovery mechanisms, including DNS TXT-record dead drops. It includes a backconnect proxy capability and has evolved toward operating a residential proxy network alongside DDoS operations. Shared infrastructure, payload behavior, command-and-control characteristics, and local Android Debug Bridge scanning link Aisuru activity to Kimwolf. Aisuru is also associated with the development lineage of kitty and AIRASHI variants. Infrastructure and tooling overlap have been reported with the Keksec ecosystem, although a definitive operator attribution is not established. Multinational law-enforcement action disrupted Aisuru command-and-control infrastructure in March 2026, after which activity resumed at a reduced level.
C2 tracking
Derp observations, rolling seven-day window
Samples
76a355200209715544d6da6186204f08a1045b7589fecfcc313f7659e9f4c226 b5cb09e12f6c9a73f1cde98f869014dc35ca8bbdec560189c885b3aadd5c0074 ce0dbbad133e181fbb2edca3873993dad17d9716aab8292757dbb19e028b9b7c db6f76b9c0db47bbb0f65535cbfa370ab0e6734c42dc48ef157e7794174b16cb e0250e6686a6f58b6e26c378630930f49acdd0df6a9dd6d1f3303e0840403df9 5f6742ad105b8eb2817d950fce6c833df229b33ae5e82649ccb41bba067d60ad Reported operators
Shared infrastructure ties the operator to the Keksec ecosystem, home to Kaitori and AISURU tooling.
Microsoft disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 15.72 terabits per second (Tbps)... It originated from a TurboMirai-class Internet of Things (IoT) botnet known as AISURU. According to data from QiAnXin XLab, the AISURU botnet is powered by nearly 300,000 infected devices, most of which are routers, security cameras, and DVR systems.
Exploited software
MITRE ATT&CK
Reporting
A March multinational operation involving the United States, Canada, and Germany disrupted infrastructure supporting the Aisiru and Kimwolf botnets, contributing to a fall in the largest observed botnet from 13.5 million devices in Q1 2026 to 2.09 million in Q2. Link11 also reported a 42% decline in DDoS attacks in Europe during the first half of 2026, partly attributing the reduction to law-enforcement actions including Operation Eastwood and the shutdown of four IoT botnets. Attackers are compensating with more powerful and resilient campaigns: Link11 recorded peaks of 2.3 Tbit/s and 322 million packets per second, with 705 TB of cumulative malicious traffic, driven by super-botnets and hijacked cloud servers. Operators are increasingly dispersing traffic sources and adopting decentralized command infrastructure; the Aeternum and Void botnets use Polygon and Ethereum smart contracts for C2 distribution. DDoS surges are also being used to conceal SQL-injection and XSS probing, requiring defenses that combine continuous traffic inspection, behavioral detection, adaptive filtering, and application-layer monitoring.
U.S., Bulgarian, Hungarian, and Romanian authorities, supported by CrowdStrike and the Shadowserver Foundation, disrupted the long-running Sality peer-to-peer botnet by seizing payload-hosting domains, dismantling control infrastructure, and sinkholing its super-peer network. The operation exploited Sality's unauthenticated peer-list protocol to redirect infected hosts away from operator-controlled infrastructure, cutting off delivery of new malware payloads and removing the botnet from the operators' control. Active since at least 2003, Sality infected more than 15,000 devices and spread by infecting Windows executables. CrowdStrike attributes the operation to SALTY SPIDER, a criminal group likely based in Russia's Republic of Bashkortostan; its infrastructure supported credential theft, spam, proxying, network exploitation, DDoS activity, and EggJagger cryptocurrency clipboard hijacking. Organizations should investigate UDP communications with 188.166.101[.]148, an indicator of Sality infection, because sinkholing prevents new payload delivery but does not remove malware from already compromised systems.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.