/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A US DOJ operation disrupted four botnets that infected 3M+ devices and includes the Aisuru and Kimwolf botnets used in a 31.4 Tbps DDoS attack in November 2025

The Aisuru, Kimwolf, JackSkid, and Mossad botnets had used clever techniques to worm into home networks, infecting …

Wired Andy Greenberg

Context & Ripple Effects

The operation follows a previously disclosed Aisuru/Kimwolf assault that Cloudflare said it mitigated at 31.4 Tbps, linking law-enforcement action to botnets already associated with unusually large DDoS capacity. The reported use of home-network worming techniques also makes the infected-device base central to the story, not merely the operators behind it.

It fits a recurring DOJ playbook: an earlier international disruption of the RSocks proxy botnet likewise targeted a network built from hijacked devices. The difference here is the concentration of four named botnets in one action, including two tied to the earlier high-volume attack.

First-order effects

  • Aisuru, Kimwolf, JackSkid, and Mossad lose operational continuity from the DOJ disruption, immediately reducing the usable infrastructure available to whoever controlled them.
  • Organizations exposed to DDoS gain near-term relief from two botnets connected to the 31.4 Tbps Aisuru/Kimwolf attack, while owners of compromised devices remain the remediation constituency.

Second-order effects

  • DDoS-for-hire and proxy operators may have to replace disrupted device capacity, making newly compromised home-network devices and alternative botnet inventory more valuable in the short term.
  • Network defenders and service providers have a clearer reason to treat consumer-device compromise as upstream DDoS risk, rather than solely an endpoint-security problem.

Third-order effects

  • Repeated botnet takedowns can constrain individual networks without resolving the supply of poorly secured devices; durable risk reduction depends on whether device owners, vendors, and providers reduce reinfection opportunities.
  • The pattern points toward cyber enforcement increasingly targeting the infrastructure behind attacks and proxy services, alongside mitigation by cloud and network providers.

The trend: Botnet defense is shifting toward a combined model of large-scale traffic mitigation and law-enforcement disruption of the compromised-device infrastructure that supplies attack capacity.

Discussion

  • @mattjay Matt Johansen on x
    DOJ just announced takedown of four major botnets - Aisuru, KimWolf, JackSkid, and Mossad. This is significant scale. > The numbers here are wild: combined 3+ million infected devices globally (hundreds of thousands in US alone), and attacks hitting 30 Tbps. That's [image]
  • @agreenberg Andy Greenberg on bluesky
    Feds just took down 4 botnets, including the Aisuru and Kimwolf botnets that carried out record-breaking DDOS attacks peaking at 30+ terabits per second, nearly three times the previous record.  DOJ says the botnets had hijacked more than three million devices. www.wired.com/stor…
  • r/technews r on reddit
    Aisuru - Largest botnet in the world, taken down in joint operation between Canadian, German, and American federal police.
  • @zephyr_z9 @zephyr_z9 on x
    Old man Wally was with Jensen 2-3 days ago LMAO [image]
  • @zephyr_z9 @zephyr_z9 on x
    Old man has a net worth of $500M Got caught swapping serial numbers using a fucking hair dryer [image]
  • @ericjgeller.com Eric Geller on bluesky
    The U.S. has seized web infrastructure that cybercriminals were using to run four major DDoS botnets powered largely by hacked IoT devices.  The botnets conducted record-breaking and costly attacks.  Canada and Germany appear to have arrested some of the operators. www.justice.go…