Cloudflare says it mitigated a 31.4 Tbps DDoS attack from the Aisuru/Kimwolf botnet in December 2025, making it the largest attack ever disclosed publicly
The Aisuru/Kimwolf botnet launched a new massive distributed denial of service (DDoS) attack that peaked at 31.4 Tbps and 200 million requests per second, setting a new record.
Context & Ripple Effects
Cloudflare has repeatedly reported rising DDoS records, from 17.2 million requests per second in 2021 to a 7.3 Tbps attack mitigated in 2025. The latest disclosure extends that documented escalation in attack bandwidth.
The new event also combines bandwidth scale with a 200 million requests-per-second peak, following Cloudflare's earlier reports of hyper-volumetric attacks exceeding 71 million requests per second. That makes it relevant to both network-capacity and application-layer defense.
First-order effects
- Cloudflare must absorb and filter traffic at a newly disclosed peak level while keeping the targeted service reachable; the event validates its mitigation infrastructure under an extreme load.
- The Aisuru/Kimwolf botnet is tied to a public record-scale incident, increasing the operational urgency for organizations exposed to DDoS disruption to review their protective capacity.
Second-order effects
- Other DDoS mitigation and cloud-edge providers face a higher demonstrated benchmark for both throughput and request-rate handling, while customers will scrutinize mitigation claims against this scale.
- Defenders will need to plan for attacks that pressure transit capacity and application-facing request handling simultaneously, rather than treating bandwidth and request floods as separate scenarios.
Third-order effects
- If record attacks continue to arrive in quick succession, large-scale traffic filtering becomes a more important differentiator for edge and cloud platforms, favoring providers with broad network capacity and automated mitigation.
- The pattern points to an escalating resilience arms race: botnet operators test larger coordinated floods, and service providers must continuously expand detection and scrubbing capabilities. The pace and ceiling of that escalation remain uncertain.
The trend: This is another data point in the shift toward ever-larger, multi-vector DDoS attacks that make network-scale automated mitigation a core internet infrastructure capability.