Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructuretelecommunications-sector-threatoperational-disruptionembedded-device-vulnerability

Aisuru/Kimwolf Botnet Sets 31.4 Tbps DDoS Record Against Cloudflare-Protected Targets

Updated 3mo agoFirst seen Jan 29, 20266 sources

Cloudflare reported mitigating a record-breaking hyper-volumetric DDoS campaign attributed to the Aisuru/Kimwolf botnet, with a peak of 31.4 Tbps and application-layer floods exceeding 200 million HTTP requests per second. Cloudflare said the activity—named “The Night Before Christmas” due to its timing—began on December 19, 2025 and targeted both Cloudflare customers and Cloudflare’s own dashboard/infrastructure, with many victims described as telecommunications providers and IT organizations.

Reporting on Cloudflare’s findings indicates the campaign consisted of thousands of individual attacks that were typically short in duration (often 1–2 minutes), with the majority peaking in the 1–5 Tbps range and 1–5 billion packets per second. The botnet was also linked to prior record-setting activity (including a previously disclosed 29.7 Tbps peak), and Cloudflare attributed the attack sources in this campaign primarily to compromised Android TV/streaming devices; Cloudflare stated the attacks were automatically detected and mitigated without triggering internal alerts.

Share:
Aisuru/Kimwolf Botnet Sets 31.4 Tbps DDoS Record Against Cloudflare-Protected Targets
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 29, 20265mo ago

Cloudflare publicly discloses the record Aisuru attack

On January 29, 2026, multiple outlets reported Cloudflare's disclosure of the December Aisuru/Kimwolf campaign, including details that the botnet relied heavily on compromised Android TV and other consumer devices.

Dec 31, 20256mo ago

Cloudflare reports 47.1 million DDoS attacks in 2025

Cloudflare's year-end reporting said it mitigated 47.1 million DDoS attacks in 2025, a 121% increase over 2024, with continued growth in Q4 and sharp increases in terabit-scale and high packet-rate attacks.

Dec 19, 20256mo ago

Record 31.4 Tbps and 200M rps attack is mitigated by Cloudflare

During the December 19 campaign, Cloudflare mitigated a publicly disclosed record DDoS event peaking at 31.4 Tbps and more than 200 million HTTP requests per second, attributing it to the Aisuru/Kimwolf botnet and saying mitigation was fully automated.

Aisuru/Kimwolf launches 'The Night Before Christmas' DDoS campaign

Beginning on December 19, 2025, the Aisuru/Kimwolf botnet launched a hyper-volumetric DDoS campaign targeting Cloudflare customers, Cloudflare infrastructure, and its dashboard, with attacks delivered in short, intense bursts.

Sep 30, 20259mo ago

Cloudflare labels Aisuru the 'apex of botnets' in Q3 2025

In its 2025 Q3 DDoS threat reporting, cited by ZDNET, Cloudflare characterized Aisuru as the 'apex of botnets' and noted its frequent targeting of telecommunications, gaming, hosting, ISP, and financial services organizations.

Jan 1, 20251y ago

Kimwolf botnet emerges and expands during 2025

Barracuda reported Kimwolf as active since 2025, portraying it as a stealthy botnet that embeds in enterprise and public-sector environments and uses dynamic communications to evade detection.

Jan 1, 20242y ago

Aisuru botnet becomes active against IoT devices

Barracuda described Aisuru as active since 2024, using automated scanning and exploitation to rapidly compromise vulnerable IoT devices and build a botnet capable of large volumetric DDoS attacks.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

35 LINKEDOpen in app
Threat actors
2 linked
Affected products
6 linked
Android TvAndroid TvBitlockerAndroid TvAndroidWhatsapp
Organizations
21 linked
CloudflareAmazon Web ServicesNetscoutZDNETGetty ImagesiStockMicrosoft CorporationAkamai TechnologiesTencentBleepingComputerDigitaloceanTom's HardwareImpervaNetflixLumen TechnologiesOracleSynthientKrebs on SecurityHetzner Online GmbHResi Rack LLCCybersecurity Dive
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.