HomeSecurityMicrosoft: Azure network hit by 15 Tbps DDoS attack

Microsoft: Azure network hit by 15 Tbps DDoS attack

Microsoft has suffered one of the most impressive – and worrying – DDoS attacks of the year, with the Aisuru botnet targeting its Azure network in an attack that reached 15.72 terabits per second . The company says the attack originated from more than 500,000 different IPs , focusing its volume on a specific public Azure address in Australia.

Microsoft Azure DDoS

The attack was based on high-rate UDP floods, which reached 3.64 billion packets per second.

As Sean Whalen, senior product manager at Azure Security, said , Aisuru is a Turbo Mirai IoT botnet , known for abusing compromised home routers and security cameras in the US and internationally. The attack did not rely on extensive source spoofing, which made it easier for providers to analyze and respond.

See also: EVALUSION: New ClickFix campaign distributes Amatera Stealer and NetSupport RAT

Botnet history with consecutive records

Aisuru wasn’t making its first “raid.” Cloudflare had linked the same botnet to one of the largest DDoS attacks of all time — a 22.2 Tbps that reached 10.6 billion packets per second (in September 2025).

Although the attack lasted just 40 seconds, its data volume was equivalent to streaming a million 4K videos playing simultaneously. Such an incident shows how sophisticated and dangerous modern botnets have become – especially IoT botnets with a huge number of infected devices.

A week before this incident, Qi'anxin's XLab team had attributed another attack to Aisuru — this time 11.5 Tbps — estimating that the botnet then controlled around 300,000 active bots.

Microsoft: Azure network hit by 15 Tbps DDoS attack

XLab also revealed that the botnet exploits vulnerabilities in popular devices: IP cameras, DVR/NVRs, Realtek chips, and routers from companies such as T-Mobile, Zyxel, D-Link, and Linksys. Its spectacular increase in size in April 2025, after the infection of 100,000 TotoLink devices, demonstrates how easily a botnet's capacity can skyrocket once a critical entry point is identified.

See also: Akira ransomware spreads to Nutanix AHV

Influence on DNS rankings and the "downloading" of domains

Journalist Brian Krebs reported earlier this month that Cloudflare removed several domains associated with the Aisuru botnet from its public “Top Domains” rankings of the most searched (based on DNS query volume) after they began to overtake legitimate sites such as Amazon, Microsoft, and Google.

The reason? Aisuru operators were flooding Cloudflare's DNS service (1.1.1.1) with fake queries, aiming to artificially boost the popularity of their domains. This practice caused the botnet's domains to appear higher than even giants like Amazon and Google, completely distorting the ranking system.

Cloudflare CEO Matthew Princeconfirmed that the company is now hiding or removing malicious domains from its rankings to prevent similar incidents from happening again.

Explosive rise in DDoS attacks worldwide

Cloudflare, in its Q1 2025 DDoS report, presented a worrying picture:

  • 198% increase in attacks on a quarterly basis
  • 358% increase year-on-year
  • 21.3 million attacks were blocked in 2024
  • Another 6.6 million targeted its own infrastructure over an 18-day period

See also: Detailed techniques for detecting the NotDoor Outlook Backdoor

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Microsoft: Azure network hit by 15 Tbps DDoS attack

The numbers show a clear reality: IoT botnets now have the potential to cause attack waves that exceed the resistance of many infrastructures, while they are constantly evolving thanks to the rapid "recruitment" of new infected devices.

The Future of DDoS: More Automated, More Aggressive

Aisuru is just one example of where the world of cyberattacks. With more and more home devices connected to the internet — and often with inadequate security — the field remains ripe for exploitation.

And the bigger botnets get, the harder it will be for companies and infrastructure to keep their shields up.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS