Aisuru Botnet Drove Record-Breaking Multi-Terabit DDoS Attacks
Researchers and network defenders linked the Aisuru botnet to a wave of hyper-volumetric distributed denial-of-service attacks that pushed internet-scale flooding to new highs. Reports described attacks reaching 11.5 Tbps and later 22.2 Tbps with 10.6 billion packets per second, with one major incident lasting about 40 seconds and being automatically mitigated by Cloudflare. Coverage from Cloudflare, The Register, Cybersecurity Dive, and QiAnXin XLab said the botnet helped fuel a broader rise in DDoS activity and turned parts of the internet into what one report characterized as a terabit-scale stress test.
Government and industry tracking indicated the botnet was not an isolated spike but an active threat affecting organizations across regions, including the UK. Germany's BSI published an Aisuru botnet profile as defenders continued cataloging its infrastructure and behavior, while media reports said British businesses were hit by record botnet-driven barrages. Across the referenced reporting, Aisuru emerged as a large-scale botnet associated with compromised devices and capable of launching short, extremely intense floods that set new benchmarks for DDoS volume and forced providers to rely on automated mitigation at massive scale.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
9 events from the most recent confirmed update back to the earliest known activity.
Germany's BSI adds Aisuru to its active botnet profiles
On 2026-03-11, Germany's Federal Office for Information Security (BSI) published an Aisuru botnet profile. The listing marked official government tracking and public documentation of the threat.
UK organizations reported hit by record Aisuru-driven DDoS wave
On 2026-02-06, reporting indicated British businesses were being battered by a record botnet-driven DDoS blitz associated with Aisuru. This reflected the botnet's continued operational impact beyond the initial record attacks.
The Register highlights Aisuru as a terabit-scale internet stress test
On 2025-12-04, The Register reported on Aisuru as a botnet behind terabit-scale DDoS activity, emphasizing its role in unprecedented internet-scale attack traffic. The article largely reflected previously disclosed attack milestones rather than a separate incident.
Cloudflare publishes full threat report on Aisuru botnet
On 2026-01-01, Cloudflare published a dedicated threat intelligence report on Aisuru, detailing how early October attacks escalated into record-setting DDoS activity. The report consolidated technical analysis and attribution around the botnet's operations.
Cloudflare reports Q3 DDoS growth fueled by Aisuru botnet
On 2025-12-03, Cloudflare's Q3 DDoS findings were reported as showing rising attack volume, with Aisuru identified as a major driver of record attacks. The reporting connected the botnet to the surge in hyper-volumetric incidents.
Aisuru activity escalates in early October with record-setting attacks
In early October 2025, attacks associated with the Aisuru botnet intensified and escalated into record-setting DDoS activity. Later reporting tied this period to terabit-scale attacks and broader operational growth by the botnet.
Cloudflare discloses a new record 22.2 Tbps DDoS attack
By 2025-09-24, Cloudflare disclosed that it had autonomously mitigated a record-breaking DDoS attack peaking at 22.2 Tbps and 10.6 billion packets per second. The attack lasted about 40 seconds and was described as nearly twice as large as the previous record event.
QiAnXin XLab publishes analysis of the Aisuru botnet
On 2025-09-15, QiAnXin XLab published research describing Aisuru as an ultra-large botnet capable of 11.5 Tbps-scale attacks. The report provided early technical details about the botnet's scale and operations.
Cloudflare mitigates an 11.5 Tbps DDoS attack linked to Aisuru
In early September 2025, Cloudflare mitigated a hyper-volumetric DDoS attack peaking at 11.5 Tbps, later attributed to the Aisuru botnet. The incident was described as one of the largest attacks observed at the time.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
7 references tracked. Mallory keeps watching after this page renders.
BSI - Steckbriefe aktueller Botnetze - Aisuru
bsi.bund.de
Open sourceDDoS deluge: Brit biz battered by record botnet blitz
theregister.com
Open sourceAisuru botnet: Early October attacks escalate into record-setting DDoS activity | Cloudflare
cloudflare.com
Open sourceAisuru botnet turns was a terabit-scale internet stress test
theregister.com
Open sourceDDoS attack volume rises in Q3, fueled by Aisuru botnet | Cybersecurity Dive
cybersecuritydive.com
Open sourceCloudflare mitigates yet another record-breaking DDoS attack-which, at 22.2 Tbps, makes it nearly twice as big as the last hyper-volumetric attack | PC Gamer
pcgamer.com
Open source史上最强?揭秘11.5T级超大规模僵尸网络AISURU的内幕
blog.xlab.qianxin.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


