HomeSecurityUS authorities "dismantle" four IoT botnets

American authorities “dismantle” four IoT botnets

U.S. authorities, working with Canada and Germany, have dismantled four of the most destructive IoT botnets that had compromised more than 3 million Internet of Things (IoT) devices, including routers and web cameras. The botnets , codenamed Aisuru, Kimwolf, JackSkid , and Mossad, were responsible for a series of DDoS attacks that could cripple almost any target. The operation is one of the largest international efforts against IoT botnets in cybersecurity history.

IoT botnets

The takedown operation resulted from coordinated action by the U.S. Department of Justice with Canadian and German authorities, targeting the command-and-control infrastructure that controls over 3 million compromised IoT devices.

See also: New DDoS botnet campaign targets IoT devices

Aisuru emerged in late 2024 and by mid-2025 was launching record-breaking DDoS attacks as it rapidly infected new IoT devices . In October 2025, it was used to install Kimwolf , a variant of Aisuru that introduced a new propagation mechanism that allowed the botnet to infect devices hidden behind the protection of the user's internal network.

On January 2, 2026, security firm Synthient publicly disclosed the vulnerability that Kimwolf was using to spread so quickly. This disclosure went some way to limiting Kimwolf's spread, but since then, several other IoT botnets have emerged that effectively copy Kimwolf's propagation methods. According to the Department of Justice, the JackSkid botnet also sought out systems on internal networks (like Kimwolf).

Aisuru 's actively infected devices increased from 50,000 to 200,000 , while in early October 2025, operators switched to Kimwolf via new domains, ports, and malware. Kimwolf issued more than 25,000 attack commands, the government said, while Mossad was blamed for about 1,000 digital sieges.

See also: Authorities dismantled the infrastructure of the phishing service Tycoon2FA

IoT botnets διάλυση από αμερικανικές αρχές DDoS επιθέσεις

IoT botnets: Advanced infection methods and detection evasion techniques

IoT botnets utilized advanced techniques to evade detection, including the use of residential proxy networks that made it difficult to trace the true origin of attacks. Android TV devices were ideal targets due to their often poor security and infrequent firmware updates. The use of wolfSSL library and encrypted communications over DoT made monitoring network traffic extremely difficult for defenders.

The perpetrators also implemented domain generation algorithms (DGA) and the use of ENS blockchain domains to maintain communication with infected systems even after takedowns. This approach demonstrates a high degree of technical expertise and preparation for long-term operations.

American authorities "disband" four IoT botnets

Protection recommendations and security measures

To protect against similar threats, experts recommend updating Android and IoT firmware, disabling unused proxies, and blocking DoT/ENS domains. Enterprises should scan for Kimwolf beacons, restrict outbound traffic to proxy networks, and deploy DDoS mitigation solutions like Cloudflare. Additionally, monitoring unusual network traffic and implementing network segmentation can limit the spread of infections.

See also: Side-Channel attacks on common IoT devices

The industry must collaborate on takedowns like the Lumen, Google and Cloudflare, while monitoring the Android TV ecosystem is essential. The successful dismantling of these IoT botnets demonstrates that international cooperation and coordination between the public and private sectors are key to addressing modern cyber threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS