Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructureoperational-disruptioncybercrime-service-ecosystem

AISURU/Kimwolf Botnet’s Record 31.4 Tbps Hyper-Volumetric DDoS Attack Mitigated by Cloudflare

Updated 3mo agoFirst seen Feb 6, 20262 sources

Cloudflare reported mitigating a record-setting hyper-volumetric DDoS attack attributed to the AISURU/Kimwolf botnet that peaked at 31.4 Tbps and lasted 35 seconds in November 2025. The activity was described as part of a broader late-2025 surge in hyper-volumetric HTTP DDoS events that Cloudflare said were automatically detected and blocked, with Q4 2025 hyper-volumetric attacks increasing 40% quarter-over-quarter and the largest attacks growing 700% compared to late 2024.

Reporting tied AISURU/Kimwolf to DDoS-for-hire style operations and additional campaigns such as “The Night Before Christmas” (starting December 19, 2025), with Cloudflare citing campaign averages around 3 Bpps, 4 Tbps, and 54 Mrps, and peaks up to 9 Bpps, 24 Tbps, and 205 Mrps. The botnet’s capabilities and impact extend beyond web-layer floods: it has been associated with UDP/TCP/GRE flooding techniques and disruption of broadband providers via traffic sourced from compromised customer devices/CPE, and it has been described as enabling other illicit activity (e.g., credential stuffing, scraping, spam, phishing); separate reporting also stated the botnet has leveraged a large pool of compromised devices, including millions of Android-based endpoints such as off-brand Android TVs.

Share:
AISURU/Kimwolf Botnet’s Record 31.4 Tbps Hyper-Volumetric DDoS Attack Mitigated by Cloudflare
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 5, 20265mo ago

Cloudflare reports major 2025 DDoS surge and AISURU/Kimwolf attribution

Cloudflare disclosed that DDoS activity surged in 2025, with 47.1 million total attacks, sharp growth in network-layer attacks, and major increases in large attacks during Q4 2025. The company also linked the record November 2025 attack to AISURU/Kimwolf and described the botnet as leveraging more than 1.8 to 2 million infected Android devices, many of them off-brand Android TVs.

Google and Cloudflare disrupt IPIDEA infrastructure

Google, working with Cloudflare, disrupted infrastructure tied to the IPIDEA residential proxy network and pursued legal action against domains used to control devices and route proxy traffic. The action targeted infrastructure associated with the AISURU/Kimwolf botnet ecosystem.

Nov 1, 20258mo ago

Cloudflare blocks 31.4 Tbps DDoS attack in November 2025

In November 2025, Cloudflare automatically detected and mitigated a record-setting hyper-volumetric HTTP DDoS attack that peaked at 31.4 Tbps and lasted 35 seconds. The attack was attributed to the AISURU/Kimwolf botnet ecosystem.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

21 LINKEDOpen in app
Threat actors
1 linked
Affected products
4 linked
AndroidWindowsOnedriveAndroid
Organizations
11 linked
CloudflareTencentDigitaloceanMicrosoft CorporationOracleXLabHetznerSecurity AffairsGoogleIPIDEAThe Hacker News
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

AISURU/Kimwolf Botnet’s Record 31.4 Tbps Hyper-Volumetric DDoS Attack Mitigated by Cloudflare | Mallory