Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructurethreat-infrastructure-trackingoperational-disruptioncritical-infrastructure-threat

Aisuru Botnet Drove Record-Breaking Multi-Terabit DDoS Attacks

Updated 22d agoFirst seen May 25, 20267 sources

Researchers and network defenders linked the Aisuru botnet to a wave of hyper-volumetric distributed denial-of-service attacks that pushed internet-scale flooding to new highs. Reports described attacks reaching 11.5 Tbps and later 22.2 Tbps with 10.6 billion packets per second, with one major incident lasting about 40 seconds and being automatically mitigated by Cloudflare. Coverage from Cloudflare, The Register, Cybersecurity Dive, and QiAnXin XLab said the botnet helped fuel a broader rise in DDoS activity and turned parts of the internet into what one report characterized as a terabit-scale stress test.

Government and industry tracking indicated the botnet was not an isolated spike but an active threat affecting organizations across regions, including the UK. Germany's BSI published an Aisuru botnet profile as defenders continued cataloging its infrastructure and behavior, while media reports said British businesses were hit by record botnet-driven barrages. Across the referenced reporting, Aisuru emerged as a large-scale botnet associated with compromised devices and capable of launching short, extremely intense floods that set new benchmarks for DDoS volume and forced providers to rely on automated mitigation at massive scale.

Share:
Aisuru Botnet Drove Record-Breaking Multi-Terabit DDoS Attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Mar 9, 20264mo ago

Germany's BSI adds Aisuru to its active botnet profiles

On 2026-03-11, Germany's Federal Office for Information Security (BSI) published an Aisuru botnet profile. The listing marked official government tracking and public documentation of the threat.

Feb 6, 20265mo ago

UK organizations reported hit by record Aisuru-driven DDoS wave

On 2026-02-06, reporting indicated British businesses were being battered by a record botnet-driven DDoS blitz associated with Aisuru. This reflected the botnet's continued operational impact beyond the initial record attacks.

Dec 4, 20257mo ago

The Register highlights Aisuru as a terabit-scale internet stress test

On 2025-12-04, The Register reported on Aisuru as a botnet behind terabit-scale DDoS activity, emphasizing its role in unprecedented internet-scale attack traffic. The article largely reflected previously disclosed attack milestones rather than a separate incident.

Dec 3, 20257mo ago

Cloudflare publishes full threat report on Aisuru botnet

On 2026-01-01, Cloudflare published a dedicated threat intelligence report on Aisuru, detailing how early October attacks escalated into record-setting DDoS activity. The report consolidated technical analysis and attribution around the botnet's operations.

Cloudflare reports Q3 DDoS growth fueled by Aisuru botnet

On 2025-12-03, Cloudflare's Q3 DDoS findings were reported as showing rising attack volume, with Aisuru identified as a major driver of record attacks. The reporting connected the botnet to the surge in hyper-volumetric incidents.

Oct 8, 20259mo ago

Aisuru activity escalates in early October with record-setting attacks

In early October 2025, attacks associated with the Aisuru botnet intensified and escalated into record-setting DDoS activity. Later reporting tied this period to terabit-scale attacks and broader operational growth by the botnet.

Sep 24, 20259mo ago

Cloudflare discloses a new record 22.2 Tbps DDoS attack

By 2025-09-24, Cloudflare disclosed that it had autonomously mitigated a record-breaking DDoS attack peaking at 22.2 Tbps and 10.6 billion packets per second. The attack lasted about 40 seconds and was described as nearly twice as large as the previous record event.

Sep 15, 20259mo ago

QiAnXin XLab publishes analysis of the Aisuru botnet

On 2025-09-15, QiAnXin XLab published research describing Aisuru as an ultra-large botnet capable of 11.5 Tbps-scale attacks. The report provided early technical details about the botnet's scale and operations.

Sep 3, 202510mo ago

Cloudflare mitigates an 11.5 Tbps DDoS attack linked to Aisuru

In early September 2025, Cloudflare mitigated a hyper-volumetric DDoS attack peaking at 11.5 Tbps, later attributed to the Aisuru botnet. The incident was described as one of the largest attacks observed at the time.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Organizations
7 linked
CorsairLenovoCloudflareHewlett Packard EnterpriseAlienwareMinisforumVelocity Micro
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Aisuru Botnet Drove Record-Breaking Multi-Terabit DDoS Attacks | Mallory