A US DOJ operation disrupted four botnets that infected 3M+ devices and includes the Aisuru and Kimwolf botnets used in a 31.4 Tbps DDoS attack in November 2025
The Aisuru, Kimwolf, JackSkid, and Mossad botnets had used clever techniques to worm into home networks, infecting …
Context & Ripple Effects
The operation follows a previously disclosed Aisuru/Kimwolf assault that Cloudflare said it mitigated at 31.4 Tbps, linking law-enforcement action to botnets already associated with unusually large DDoS capacity. The reported use of home-network worming techniques also makes the infected-device base central to the story, not merely the operators behind it.
It fits a recurring DOJ playbook: an earlier international disruption of the RSocks proxy botnet likewise targeted a network built from hijacked devices. The difference here is the concentration of four named botnets in one action, including two tied to the earlier high-volume attack.
First-order effects
- Aisuru, Kimwolf, JackSkid, and Mossad lose operational continuity from the DOJ disruption, immediately reducing the usable infrastructure available to whoever controlled them.
- Organizations exposed to DDoS gain near-term relief from two botnets connected to the 31.4 Tbps Aisuru/Kimwolf attack, while owners of compromised devices remain the remediation constituency.
Second-order effects
- DDoS-for-hire and proxy operators may have to replace disrupted device capacity, making newly compromised home-network devices and alternative botnet inventory more valuable in the short term.
- Network defenders and service providers have a clearer reason to treat consumer-device compromise as upstream DDoS risk, rather than solely an endpoint-security problem.
Third-order effects
- Repeated botnet takedowns can constrain individual networks without resolving the supply of poorly secured devices; durable risk reduction depends on whether device owners, vendors, and providers reduce reinfection opportunities.
- The pattern points toward cyber enforcement increasingly targeting the infrastructure behind attacks and proxy services, alongside mitigation by cloud and network providers.
The trend: Botnet defense is shifting toward a combined model of large-scale traffic mitigation and law-enforcement disruption of the compromised-device infrastructure that supplies attack capacity.