Executive Summary
In October 2025, the Aisuru botnet orchestrated the largest recorded distributed denial-of-service (DDoS) attacks to date, leveraging over 300,000 compromised IoT devices primarily hosted on major U.S. ISPs such as AT&T, Comcast, and Verizon. The botnet, evolved from Mirai code, exploited insecure or outdated IoT firmware, driving attack volumes to nearly 30 terabits per second. Recurrent DDoS waves severely disrupted online gaming infrastructure and collateral users, overwhelming both DDoS mitigation providers and ISPs, and causing service dropouts and customer impact across multiple networks.
This incident exemplifies the rising scale and sophistication of IoT-based botnets and exposes urgent deficiencies in outbound DDoS filtering at the ISP level. The Aisuru event also highlights a growing threat trend: attackers using compromised consumer IoT to reinforce both DDoS infrastructure and residential proxy networks, broadening attacker capabilities and the attack surface for businesses and critical providers.
Why This Matters Now
The escalation of the Aisuru botnet's activity reveals an urgent industry vulnerability: inadequate controls and filtering against large-scale outbound DDoS originating from consumer IoT on major ISPs. Network operators, cloud-based services, and gaming providers face amplified operational, reputational, and compliance risks as attacker capabilities rapidly outpace typical mitigation defenses.
Attack Path Analysis
The Aisuru botnet operators compromised large volumes of IoT devices via exploitation of unpatched firmware and default credentials. After initial access, attackers leveraged weak device security to escalate privileges and install persistent malware. The compromised devices permitted lateral movement across ISPs and new regions, further expanding botnet reach. The attackers maintained command and control by embedding robust remote management, directing infected IoT devices globally. Exfiltration was largely indirect, leveraging devices for network reconnaissance and to enroll them in the botnet infrastructure. Ultimately, the attackers unleashed massive DDoS attacks, generating record-breaking outbound traffic that disrupted gaming providers and ISPs at scale.
Kill Chain Progression
Initial Compromise
Description
Attackers scanned for and exploited IoT devices running outdated firmware or factory-default credentials, gaining initial access to large numbers of consumer devices.
Related CVEs
CVE-2017-5259
CVSS 9.8A command injection vulnerability in Cambium Networks' cnPilot routers allows remote attackers to execute arbitrary commands via crafted HTTP requests.
Affected Products:
Cambium Networks cnPilot Routers – All versions prior to firmware update addressing CVE-2017-5259
Exploit Status:
exploited in the wildCVE-2023-28771
CVSS 9.8A command injection vulnerability in Zyxel devices allows remote attackers to execute arbitrary commands via crafted packets.
Affected Products:
Zyxel Various Zyxel Devices – Specific versions vulnerable; refer to official Zyxel advisories
Exploit Status:
exploited in the wildCVE-2023-50381
CVSS 9.8A buffer overflow vulnerability in Realtek Jungle SDK allows remote attackers to execute arbitrary code via crafted network packets.
Affected Products:
Realtek Jungle SDK – Specific versions vulnerable; refer to official Realtek advisories
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Network Denial of Service
Acquire Infrastructure: Botnet
Exploitation of Remote Services
Network Share Discovery
Exploit Public-Facing Application
Brute Force: Password Guessing
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Maintain Secure Systems and Software
Control ID: 6.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Requirements
Control ID: Article 11
CISA Zero Trust Maturity Model 2.0 – Micro-Segmentation and Network Resilience
Control ID: Network: Segmentation
NIS2 Directive – Cybersecurity Risk Management and Incident Reporting
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
DDoS botnet targets US ISPs like AT&T, Comcast, Verizon with 30Tbps attacks, overwhelming network infrastructure and requiring enhanced egress filtering capabilities.
Internet
Gaming servers and online services face record-breaking DDoS attacks causing widespread outages, requiring million-dollar monthly mitigation investments and zero trust segmentation.
Consumer Electronics
IoT devices including routers and security cameras compromised as botnet sources, exposing 300,000 devices through insecure firmware and default configurations.
Computer Games
Minecraft servers specifically targeted with 15Tbps attacks causing provider ejections and service disruptions, highlighting need for specialized DDoS protection services.
Sources
- DDoS Botnet Aisuru Blankets US ISPs in Record DDoShttps://krebsonsecurity.com/2025/10/ddos-botnet-aisuru-blankets-us-isps-in-record-ddos/Verified
- Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbpshttps://www.securityweek.com/aisuru-botnet-powers-record-ddos-attack-peaking-at-29-tbps/Verified
- Aisuru Botnet Emerges as 2025’s Largest DDoS Threathttps://www.ampcuscyber.com/shadowopsintel/aisuru-botnet-ddos-attacks-record/Verified
- Aisuru Botnet Behind Record 20Tb/sec DDoS Attackshttps://www.thecortexprotocol.com/threat/aisuru-botnet-20tb-ddosVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, strict egress controls, and threat detection could have constrained Aisuru's propagation, stopped outbound bot traffic, and enabled rapid detection and mitigation of IoT abuse within ISP or enterprise networks.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of anomalous device activity and connections.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility restricts unauthorized privilege gains across hybrid environments.
Control: Zero Trust Segmentation
Mitigation: Segmentation policies isolate infected devices, restricting east-west spread of malware.
Control: Inline IPS (Suricata)
Mitigation: Malicious C2 communications detected and blocked in-line.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized outbound traffic from IoT devices is blocked or flagged.
Mass outbound DDoS traffic detected, rate-limited, and blocked at the network perimeter.
Impact at a Glance
Affected Business Functions
- Network Operations
- Customer Services
- Online Gaming Platforms
Estimated downtime: 1 days
Estimated loss: $5,000,000
No specific data exposure reported; primary impact involves service disruption and potential reputational damage.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation to isolate IoT devices and limit east-west malware spread.
- • Implement strict egress policies and FQDN filtering to prevent compromised device C2 and outbound attack traffic.
- • Deploy inline IPS and threat detection to rapidly identify scanning, exploitation, and anomalous network behaviors.
- • Mandate centralized visibility and policy enforcement across all on-prem, hybrid, and cloud environments for early incident containment.
- • Prioritize continuous firmware management and anomaly monitoring for all connected devices, especially those unable to support endpoint agents.



