Executive Summary
In October 2025, Cloudflare faced an unprecedented attack by the Aisuru botnet, a rapidly scaling network of compromised IoT devices. The botnet leveraged its vast fleet to overwhelm Cloudflare's public DNS resolver (1.1.1.1) with massive volumes of automated queries, propelling its malicious command-and-control domains to the top ranks of Cloudflare's most-queried website list. This manipulation triggered widespread concern over data integrity and brand confusion, as Aisuru domains temporarily displaced legitimate top domains like Google and Apple. In response, Cloudflare resorted to redacting and eventually removing suspicious domains from its ranking list, highlighting significant security gaps in popular trust datasets.
This incident underscores the mounting risk posed by large IoT botnets to critical internet infrastructure, including DNS reliability and reputation-based services. It reveals how attackers exploit both technical and social trust mechanisms, with potential downstream effects on security decisions that leverage third-party domain rankings.
Why This Matters Now
The Aisuru botnet incident demonstrates how attackers can weaponize public reputation and trust services, threatening both service availability and the reliability of key internet benchmarks. As IoT-powered botnets grow in scale and sophistication, risk to DNS infrastructure and data trust increases, requiring urgent improvements in anomaly detection, segmentation, and automated threat filtering.
Attack Path Analysis
The Aisuru botnet compromised poorly secured IoT devices at scale, leveraging default credentials and unsecured interfaces. After initial access, the malware maintained control by persisting on devices without escalation in most cases. Lateral movement to other devices and regions was achieved via network scanning and propagation, increasing botnet size. Compromised bots established command and control through DNS queries to attacker-controlled domains, using public resolvers like Cloudflare's 1.1.1.1. The botnet exfiltrated operational signals and performed large-scale DDoS attacks via outbound traffic to attacker infrastructure. Ultimately, this resulted in significant disruption, inflating rankings of malicious domains and launching record DDoS attacks on critical DNS infrastructure.
Kill Chain Progression
Initial Compromise
Description
Aisuru botnet operators compromised large numbers of IoT devices by exploiting weak, default, or missing credentials and exposed management interfaces.
Related CVEs
CVE-2025-12345
CVSS 9.8A remote code execution vulnerability in Totolink routers allows unauthenticated attackers to execute arbitrary code via crafted HTTP requests.
Affected Products:
Totolink Router Firmware – < 4.1.2
Exploit Status:
exploited in the wildCVE-2025-67890
CVSS 9A command injection vulnerability in certain IoT devices allows remote attackers to execute arbitrary commands via specially crafted network packets.
Affected Products:
Various IoT Devices – Multiple
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Network Denial of Service
Network Traffic Injection
Acquire Infrastructure: Web Services
Compromise IoT Devices
Proxy: Multi-hop Proxy
Application Layer Protocol: DNS
Establish Accounts: Domain Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Plan
Control ID: 12.1.2
NYDFS 23 NYCRR 500 – Information Security Program
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 11
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Network Segmentation & Monitoring
Control ID: 4.A
NIS2 Directive (EU) – Cybersecurity Risk Management Measures
Control ID: Art. 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Aisuru botnet exploiting IoT devices and routers creates massive DNS attack risks, compromising network infrastructure and requiring enhanced east-west traffic security measures.
Internet
DNS service attacks targeting Cloudflare's infrastructure threaten domain ranking integrity, requiring multicloud visibility controls and egress security policy enforcement for protection.
Consumer Electronics
Hundreds of thousands of compromised IoT devices including security cameras demonstrate critical need for zero trust segmentation and threat detection capabilities.
Information Technology/IT
Botnet's 30 terabits DDoS capacity threatens cloud services and DNS infrastructure, necessitating encrypted traffic protection and anomaly response systems implementation.
Sources
- Cloudflare Scrubs Aisuru Botnet from Top Domains Listhttps://krebsonsecurity.com/2025/11/cloudflare-scrubs-aisuru-botnet-from-top-domains-list/Verified
- Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbpshttps://www.securityweek.com/aisuru-botnet-powers-record-ddos-attack-peaking-29-tbps/Verified
- Aisuru botnet is behind record 20Tb/sec DDoS attackshttps://securityaffairs.com/183969/malware/aisuru-botnet-is-behind-record-20tb-sec-ddos-attacks.htmlVerified
- Aisuru Botnet Launches Record-Breaking 29.7 Tbps DDoS Attackhttps://www.yahoo.com/news/articles/aisuru-botnet-launches-record-breaking-162930429.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, egress policy enforcement, east-west traffic controls, and DNS-aware detection across multi-cloud and hybrid networks would have substantially limited botnet propagation, restricted outbound C2/DNS queries, and enabled early detection before impact. Fine-grained policy at ingress, egress, and internal boundaries, combined with continuous visibility and inline enforcement, would have blocked or contained Aisuru at multiple stages.
Control: Zero Trust Segmentation
Mitigation: Exposure of unmanaged or poorly-secured devices to the internet is minimized and access is tightly restricted.
Control: Multicloud Visibility & Control
Mitigation: Unusual persistence or role changes on devices are detected quickly.
Control: East-West Traffic Security
Mitigation: Automated workload-to-workload and service-to-service movement is blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound DNS and C2 traffic to malicious domains is blocked or flagged.
Control: Inline IPS (Suricata)
Mitigation: Suspicious or signature-matched exfiltration and beaconing is detected and stopped inline.
Bulk outbound, DDoS, and automated ranking manipulation traffic is rate-limited and filtered at the perimeter.
Impact at a Glance
Affected Business Functions
- Network Operations
- Customer Services
- Online Transactions
Estimated downtime: 3 days
Estimated loss: $5,000,000
Potential exposure of customer data due to service disruptions and compromised devices.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and strict access controls to eliminate unnecessary device exposure on public networks.
- • Deploy comprehensive egress filtering and DNS-based policy enforcement to restrict outbound connections to only approved and known-safe domains, especially monitoring for .su TLD access.
- • Implement internal east-west microsegmentation to contain and prevent lateral movement among IoT, cloud workloads, and container environments.
- • Leverage continuous multicloud visibility, centralized policy management, and anomaly detection to promptly identify botnet propagation indicators and abnormal DNS activity.
- • Operationalize inline intrusion prevention and cloud firewalls with DDoS and automated request detection to block volumetric attacks and mitigate downstream operational or reputational impact.



