U.S. authorities, working with Canada and Germany, have dismantled four of the most destructive IoT botnets that had compromised more than 3 million Internet of Things (IoT) devices, including routers and web cameras. The botnets , codenamed Aisuru, Kimwolf, JackSkid , and Mossad, were responsible for a series of DDoS attacks that could cripple almost any target. The operation is one of the largest international efforts against IoT botnets in cybersecurity history.

The takedown operation resulted from coordinated action by the U.S. Department of Justice with Canadian and German authorities, targeting the command-and-control infrastructure that controls over 3 million compromised IoT devices.
See also: New DDoS botnet campaign targets IoT devices
Aisuru emerged in late 2024 and by mid-2025 was launching record-breaking DDoS attacks as it rapidly infected new IoT devices . In October 2025, it was used to install Kimwolf , a variant of Aisuru that introduced a new propagation mechanism that allowed the botnet to infect devices hidden behind the protection of the user's internal network.
On January 2, 2026, security firm Synthient publicly disclosed the vulnerability that Kimwolf was using to spread so quickly. This disclosure went some way to limiting Kimwolf's spread, but since then, several other IoT botnets have emerged that effectively copy Kimwolf's propagation methods. According to the Department of Justice, the JackSkid botnet also sought out systems on internal networks (like Kimwolf).
Aisuru 's actively infected devices increased from 50,000 to 200,000 , while in early October 2025, operators switched to Kimwolf via new domains, ports, and malware. Kimwolf issued more than 25,000 attack commands, the government said, while Mossad was blamed for about 1,000 digital sieges.
See also: Authorities dismantled the infrastructure of the phishing service Tycoon2FA

IoT botnets: Advanced infection methods and detection evasion techniques
IoT botnets utilized advanced techniques to evade detection, including the use of residential proxy networks that made it difficult to trace the true origin of attacks. Android TV devices were ideal targets due to their often poor security and infrequent firmware updates. The use of wolfSSL library and encrypted communications over DoT made monitoring network traffic extremely difficult for defenders.
The perpetrators also implemented domain generation algorithms (DGA) and the use of ENS blockchain domains to maintain communication with infected systems even after takedowns. This approach demonstrates a high degree of technical expertise and preparation for long-term operations.

Protection recommendations and security measures
To protect against similar threats, experts recommend updating Android and IoT firmware, disabling unused proxies, and blocking DoT/ENS domains. Enterprises should scan for Kimwolf beacons, restrict outbound traffic to proxy networks, and deploy DDoS mitigation solutions like Cloudflare. Additionally, monitoring unusual network traffic and implementing network segmentation can limit the spread of infections.
See also: Side-Channel attacks on common IoT devices
The industry must collaborate on takedowns like the Lumen, Google and Cloudflare, while monitoring the Android TV ecosystem is essential. The successful dismantling of these IoT botnets demonstrates that international cooperation and coordination between the public and private sectors are key to addressing modern cyber threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
