The Containment Era is here. →Explore

Executive Summary

In mid-2025, the Aisuru botnet—already infamous for record-shattering distributed denial-of-service (DDoS) attacks—shifted tactics, repurposing hundreds of thousands of compromised Internet of Things (IoT) devices to fuel residential proxy networks. Initially detected in August 2024, Aisuru rapidly infected over 700,000 vulnerable routers and cameras, enabling DDoS attacks reaching up to 30 terabits per second. As global internet providers struggled to mitigate these waves, Aisuru’s operators began renting bot-infected devices as residential proxies, granting cybercriminals more effective means to anonymize web scraping, credential stuffing, and data harvesting operations.

This incident marks a significant escalation in how botnets are monetized, as botnet-powered residential proxies become a key enabler for content scraping—especially by AI firms seeking vast datasets. The pivot highlights a rising convergence between traditional cybercrime and emerging AI-driven abuse, challenging defenders to address both volumetric attack trends and subtle, persistent data exfiltration.

Why This Matters Now

Aisuru’s evolution demonstrates how botnets are adapting to deliver both overt and covert threats—combining massive DDoS disruptions with the stealthy abuse of residential proxies to power widespread data harvesting and AI training operations. As cybercriminals and AI companies alike exploit these proxy networks, organizations face urgent new risks to their data, reputation, and compliance posture.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident highlights gaps in east-west traffic security, lack of visibility over IoT endpoints, and insufficient threat detection across hybrid environments, posing risks to frameworks like PCI DSS, NIST 800-53, and HIPAA.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, network isolation, and comprehensive egress controls could have significantly hindered Aisuru's ability to compromise, propagate, control, and monetize cloud-connected devices. Inline policy enforcement, threat detection, and east-west traffic controls are critical in constraining botnet behaviors and externalization of attacks.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Limits attacker reach and device exposure at the network perimeter and internal segments.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Detects malicious installation behaviors and unauthorized privilege usage.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Prevents unauthorized device-to-device and workload-to-workload propagation.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Blocks known malicious C2 communication signatures and detects novel C2 traffic patterns.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unauthorized outbound/bandwidth-intensive traffic to unapproved domains and destinations.

Impact (Mitigations)

Enables rapid threat identification and mitigation during active attacks.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • Customer Services
  • Online Transactions
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of customer data due to compromised network devices.

Recommended Actions

  • Implement Zero Trust network segmentation and least-privilege microsegmentation to minimize device and workload exposure.
  • Enforce strict egress filtering and application-aware outbound policies to block unauthorized proxy and scraping traffic.
  • Deploy inline IPS/IDS with threat intelligence updates to detect and prevent C2 communication and DDoS activity.
  • Increase east-west traffic monitoring and anomaly detection to immediately spot and contain lateral botnet propagation.
  • Centralize policy enforcement and multi-cloud visibility for rapid response and cross-environment consistency.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image