HomeSecurityThe AISURU Botnet behind the massive 11.5 Tbps DDoS attack

AISURU Botnet Behind Massive 11.5 Tbps DDoS Attack

Since early 2025, the cybersecurity community has observed an unprecedented increase in the bandwidth of distributed denial-of-service (DDoS) attacks, culminating in a record-breaking 11.5 Tbps attack attributed to the AISURU botnet.

See also: L7 Botnet compromised 5.76 million devices for mass attacks

Botnet AISURU

Emerging from XLab ’s ongoing monitoring of global DDoS incidents , this botnet leveraged compromised firmware on routers to amass approximately 300,000 active devices worldwide. Researchers first identified unusual spikes in malicious traffic targeting major infrastructure providers, prompting deeper investigation into the underlying threat.

XLab analysts noted striking similarities between AISURU's attack methodology and previous campaigns, however the scale and complexity of this operation far surpassed previous milestones.

The spread of AISURU began in April 2025, when threat actors exploited a vulnerability in the firmware update servers of Totolink routers. By changing the firmware URL to point to a malicious script, any device that was running an automatic update was infected. Within a few weeks, the size of the AISURU network grew to over 100,000 routers, and by September 2025, the AISURU botnet had consolidated approximately 300,000 nodes.

XLab researchers identified the use of GRE tunneling to distribute traffic loads across multiple command and control (C2) servers, allowing the botnet to orchestrate a simultaneous flood of packets that overwhelmed target networks with ease.

The impact of the 11.5 Tbps attack was felt globally as service providers struggled to mitigate the flood of SYN, UDP and DNS amplification requests. Affected organizations reported intermittent outages and service degradation, highlighting the power of combining large-scale IoT breaches with advanced evasion techniques.

See also: New NightshadeC2 botnet bypasses Windows Defender

AISURU Botnet Behind Massive 11.5 Tbps DDoS Attack
AISURU Botnet Behind Massive 11.5 Tbps DDoS Attack

XLab analysts identified the rapid shift from traditional amplification vectors to specially crafted packet sequences designed to bypass legacy mitigation tools, an innovation that allowed the AISURU botnet to set new world records in DDoS performance.

While AISURU's distributed architecture and bandwidth capacity are impressive in themselves, the malware's underlying behavior reveals a deeper level of technical sophistication. Its dual-version propagation engine shows continuous evolution, incorporating both zero-day exploits and known N-day vulnerabilities to extend its reach.

Equally concerning is its modular design, which facilitates rapid updates to encryption, communication protocols, and attack commands without requiring a complete overhaul of the malware's code.

A closer look at the AISURU botnet infection mechanism reveals a deceptively simple yet devastating approach. In April 2025, attackers compromised Totolink’s firmware update server, planting a shell script named t.sh that redirected devices to download the AISURU payload.

Once executed, the script set up persistent execution by modifying /etc/rc.local entries and disabling the Linux OOM Killer via /proc/self/oom_score_adj , ensuring that the bot remained persistent across reboots. The payload binary, renamed libcow.so , evaded detection by pretending to be a common system daemon such as telnetd or dhclient.

See also: Google sues BadBox 2.0 botnet that infects 10 million devices

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

AISURU Botnet Behind Massive 11.5 Tbps DDoS Attack
AISURU Botnet Behind Massive 11.5 Tbps DDoS Attack

Upon initialization, the AISURU botnet performs environment checks to terminate itself under virtual or analytical environments, scanning for virtual objects and debugging tools. It then establishes a secure channel with the C2 servers via a custom AES-XOR, exchanging commands ranging from DDoS instructions to home proxy assignments.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS