The Containment Era is here. →Explore

Executive Summary

In October 2025, Cloudflare faced an unprecedented attack by the Aisuru botnet, a rapidly scaling network of compromised IoT devices. The botnet leveraged its vast fleet to overwhelm Cloudflare's public DNS resolver (1.1.1.1) with massive volumes of automated queries, propelling its malicious command-and-control domains to the top ranks of Cloudflare's most-queried website list. This manipulation triggered widespread concern over data integrity and brand confusion, as Aisuru domains temporarily displaced legitimate top domains like Google and Apple. In response, Cloudflare resorted to redacting and eventually removing suspicious domains from its ranking list, highlighting significant security gaps in popular trust datasets.

This incident underscores the mounting risk posed by large IoT botnets to critical internet infrastructure, including DNS reliability and reputation-based services. It reveals how attackers exploit both technical and social trust mechanisms, with potential downstream effects on security decisions that leverage third-party domain rankings.

Why This Matters Now

The Aisuru botnet incident demonstrates how attackers can weaponize public reputation and trust services, threatening both service availability and the reliability of key internet benchmarks. As IoT-powered botnets grow in scale and sophistication, risk to DNS infrastructure and data trust increases, requiring urgent improvements in anomaly detection, segmentation, and automated threat filtering.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Aisuru used a vast array of infected IoT devices to flood Cloudflare’s DNS with automated queries, artificially boosting malicious domains into top public rankings.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust segmentation, egress policy enforcement, east-west traffic controls, and DNS-aware detection across multi-cloud and hybrid networks would have substantially limited botnet propagation, restricted outbound C2/DNS queries, and enabled early detection before impact. Fine-grained policy at ingress, egress, and internal boundaries, combined with continuous visibility and inline enforcement, would have blocked or contained Aisuru at multiple stages.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Exposure of unmanaged or poorly-secured devices to the internet is minimized and access is tightly restricted.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Unusual persistence or role changes on devices are detected quickly.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Automated workload-to-workload and service-to-service movement is blocked.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound DNS and C2 traffic to malicious domains is blocked or flagged.

Exfiltration

Control: Inline IPS (Suricata)

Mitigation: Suspicious or signature-matched exfiltration and beaconing is detected and stopped inline.

Impact (Mitigations)

Bulk outbound, DDoS, and automated ranking manipulation traffic is rate-limited and filtered at the perimeter.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • Customer Services
  • Online Transactions
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of customer data due to service disruptions and compromised devices.

Recommended Actions

  • Enforce zero trust segmentation and strict access controls to eliminate unnecessary device exposure on public networks.
  • Deploy comprehensive egress filtering and DNS-based policy enforcement to restrict outbound connections to only approved and known-safe domains, especially monitoring for .su TLD access.
  • Implement internal east-west microsegmentation to contain and prevent lateral movement among IoT, cloud workloads, and container environments.
  • Leverage continuous multicloud visibility, centralized policy management, and anomaly detection to promptly identify botnet propagation indicators and abnormal DNS activity.
  • Operationalize inline intrusion prevention and cloud firewalls with DDoS and automated request detection to block volumetric attacks and mitigate downstream operational or reputational impact.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image