Executive Summary
In mid-2025, the Aisuru botnet—already infamous for record-shattering distributed denial-of-service (DDoS) attacks—shifted tactics, repurposing hundreds of thousands of compromised Internet of Things (IoT) devices to fuel residential proxy networks. Initially detected in August 2024, Aisuru rapidly infected over 700,000 vulnerable routers and cameras, enabling DDoS attacks reaching up to 30 terabits per second. As global internet providers struggled to mitigate these waves, Aisuru’s operators began renting bot-infected devices as residential proxies, granting cybercriminals more effective means to anonymize web scraping, credential stuffing, and data harvesting operations.
This incident marks a significant escalation in how botnets are monetized, as botnet-powered residential proxies become a key enabler for content scraping—especially by AI firms seeking vast datasets. The pivot highlights a rising convergence between traditional cybercrime and emerging AI-driven abuse, challenging defenders to address both volumetric attack trends and subtle, persistent data exfiltration.
Why This Matters Now
Aisuru’s evolution demonstrates how botnets are adapting to deliver both overt and covert threats—combining massive DDoS disruptions with the stealthy abuse of residential proxies to power widespread data harvesting and AI training operations. As cybercriminals and AI companies alike exploit these proxy networks, organizations face urgent new risks to their data, reputation, and compliance posture.
Attack Path Analysis
The attackers initially compromised a vast network of poorly secured IoT devices through exploitation of weak credentials and software vulnerabilities. They escalated privileges by installing custom malware/SDKs enabling broader device control and persistence. Lateral movement occurred as the botnet propagated across network segments and regions, enrolling diverse CPEs in the botnet. The compromised devices established command and control channels via DNS and HTTP, receiving instructions from shifting C2 servers. Once control was achieved, devices were used both to launch high-bandwidth DDoS attacks and to facilitate proxy-based data egress and anonymized cybercrime. Ultimately, the impact included business disruption for ISPs through DDoS floods, widespread proxy abuse, and monetization of residential IPs for illegal activities.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited weak/default credentials and unpatched vulnerabilities in Internet-facing IoT devices (routers, cameras) to gain initial access.
Related CVEs
CVE-2017-5259
CVSS 9.8A command injection vulnerability in Cambium Networks' cnPilot routers allows remote attackers to execute arbitrary commands via crafted input.
Affected Products:
Cambium Networks cnPilot Routers – All versions prior to firmware update addressing CVE-2017-5259
Exploit Status:
exploited in the wildCVE-2023-28771
CVSS 9.8A command injection vulnerability in Zyxel devices allows remote attackers to execute arbitrary commands via crafted input.
Affected Products:
Zyxel Various Zyxel Devices – All versions prior to firmware update addressing CVE-2023-28771
Exploit Status:
exploited in the wildCVE-2023-50381
CVSS 9.8A command injection vulnerability in Realtek Jungle SDK allows remote attackers to execute arbitrary commands via crafted input.
Affected Products:
Realtek Jungle SDK – All versions prior to firmware update addressing CVE-2023-50381
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Create Account: Local Account
Ingress Tool Transfer
Proxy: External Proxy
Network Denial of Service: Direct Network Flood
Acquire Infrastructure: Web Services
Application Layer Protocol: Web Protocols
Phishing: Spearphishing Attachment
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Network segmentation
Control ID: 1.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT risk management framework
Control ID: Art. 10
CISA ZTMM 2.0 – Maintain complete asset inventory
Control ID: Asset Management - Inventory
NIS2 Directive – Supply chain security
Control ID: Art. 21(2)d
PCI DSS 4.0 – Incident Response Plan
Control ID: 12.10
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
ISPs face operational disruption from 1.5Tb/sec DDoS attacks causing router failures and degraded service for customers adjacent to infected devices.
Internet
Content platforms vulnerable to AI-driven scraping through residential proxies, with Reddit lawsuit highlighting unauthorized data harvesting bypassing security restrictions.
Computer Software/Engineering
AI companies increasingly rely on residential proxy networks for data collection, creating compliance risks and enabling aggressive content scraping activities.
Consumer Electronics
IoT devices including routers and security cameras compromised at scale, with 700,000+ devices converted from DDoS weapons to residential proxy nodes.
Sources
- Aisuru Botnet Shifts from DDoS to Residential Proxieshttps://krebsonsecurity.com/2025/10/aisuru-botnet-shifts-from-ddos-to-residential-proxies/Verified
- Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbpshttps://www.securityweek.com/aisuru-botnet-powers-record-ddos-attack-peaking-29-tbps/Verified
- Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hostshttps://thehackernews.com/2025/12/record-297-tbps-ddos-attack-linked-to.htmlVerified
- Aisuru botnet is behind record 20Tb/sec DDoS attackshttps://securityaffairs.com/183969/malware/aisuru-botnet-is-behind-record-20tb-sec-ddos-attacks.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, network isolation, and comprehensive egress controls could have significantly hindered Aisuru's ability to compromise, propagate, control, and monetize cloud-connected devices. Inline policy enforcement, threat detection, and east-west traffic controls are critical in constraining botnet behaviors and externalization of attacks.
Control: Zero Trust Segmentation
Mitigation: Limits attacker reach and device exposure at the network perimeter and internal segments.
Control: Threat Detection & Anomaly Response
Mitigation: Detects malicious installation behaviors and unauthorized privilege usage.
Control: East-West Traffic Security
Mitigation: Prevents unauthorized device-to-device and workload-to-workload propagation.
Control: Inline IPS (Suricata)
Mitigation: Blocks known malicious C2 communication signatures and detects novel C2 traffic patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized outbound/bandwidth-intensive traffic to unapproved domains and destinations.
Enables rapid threat identification and mitigation during active attacks.
Impact at a Glance
Affected Business Functions
- Network Operations
- Customer Services
- Online Transactions
Estimated downtime: 3 days
Estimated loss: $5,000,000
Potential exposure of customer data due to compromised network devices.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust network segmentation and least-privilege microsegmentation to minimize device and workload exposure.
- • Enforce strict egress filtering and application-aware outbound policies to block unauthorized proxy and scraping traffic.
- • Deploy inline IPS/IDS with threat intelligence updates to detect and prevent C2 communication and DDoS activity.
- • Increase east-west traffic monitoring and anomaly detection to immediately spot and contain lateral botnet propagation.
- • Centralize policy enforcement and multi-cloud visibility for rapid response and cross-environment consistency.



