DDoS botnets are rebuilding quickly after authorities disrupted two of the largest known operations, Kimwolf and Aisuru.

Researchers warn that takedowns can reduce a botnet’s immediate impact, but they do not remove the insecure devices that made it possible. As a result, new groups are competing for the same pool of exposed routers, cameras, Android devices and other connected hardware.

The latest findings show that botnet activity remains a global problem despite recent enforcement action.

Aisuru infrastructure grew after disruption

A major operation disrupted Aisuru and Kimwolf in March. Authorities also arrested a Canadian man suspected of operating Kimwolf.

The action removed Kimwolf as an active botnet. However, researchers say Aisuru recovered rapidly. Within four months, the known infrastructure linked to Aisuru had more than doubled compared with its size before the disruption.

Aisuru now accounts for an estimated 33% of global DDoS attack traffic, according to recent industry data. The group previously drew attention for attacks at terabit-per-second scale.

Large DDoS botnets overwhelm websites and networks by directing traffic from huge numbers of compromised devices at a target. In recent years, attacks at this scale have become increasingly common.

Kimwolf’s model spread to rival groups

Kimwolf may no longer operate, but its methods have spread. Researchers identified more than 20 competing botnets that appear to have adopted parts of its model.

The number of active daily DDoS endpoints has climbed sharply over the past year. Researchers estimate that it rose from around one million devices to between eight and nine million.

Competition has changed the shape of many attacks. Median attacks now involve around 20,000 to 30,000 IP addresses, compared with the hundreds of thousands linked to some earlier Kimwolf campaigns.

That does not make the threat less serious. A smaller attack can still disrupt a business, public service or online platform. The growing number of operators also makes the ecosystem harder to track and dismantle.

Insecure devices keep feeding botnets

The underlying problem is the sheer number of poorly secured devices connected to the internet. Aisuru has targeted routers, CCTV systems, Android TV boxes and other internet of things devices.

Many such products still use factory-default credentials or run software with known vulnerabilities. Owners may never install updates, while some devices stop receiving support long before they leave service.

Researchers also highlighted a continuing issue with residential proxy networks. These networks can expose home devices to attackers, especially when inexpensive Android hardware includes unwanted proxy software or insecure settings.

This creates a persistent supply of devices that botnet operators can recruit. Removing command-and-control servers can disrupt an operation, but replacement infrastructure can emerge if vulnerable endpoints remain online.

Manufacturers and users share responsibility

Researchers identified problems across the device supply chain. Component makers may release insecure software elements, manufacturers may fail to catch them during production, and users may continue to rely on outdated products.

Device owners can reduce their own exposure by changing default passwords, installing security updates and replacing unsupported hardware. Businesses should also maintain an inventory of connected devices and remove unnecessary internet access.

However, lasting progress requires manufacturers to deliver secure defaults and reliable long-term updates.

Conclusion

DDoS botnets continue to evolve because their operators can still find millions of vulnerable devices. The Kimwolf and Aisuru disruption weakened major players, but it also showed that enforcement alone cannot solve the problem. Stronger security across the entire device ecosystem is needed to prevent the next generation of botnets.


0 responses to “DDoS Botnets Multiply After Kimwolf and Aisuru Takedowns”