A US DOJ operation disrupted four botnets that infected 3M+ devices and includes the Aisuru and Kimwolf botnets used in a 31.4 Tbps DDoS attack in November 2025
Context & Ripple Effects
The operation follows a previously disclosed 31.4 Tbps attack attributed to Aisuru and Kimwolf, linking an unusually large DDoS event to a broader infected-device network. It also extends a DOJ pattern that includes the DanaBot charges and an earlier RSocks disruption, targeting botnet infrastructure rather than only individual attacks.
First-order effects
- Aisuru, Kimwolf, and two other disrupted botnets lose operational continuity, reducing the immediate pool of more than 3 million compromised devices available for DDoS or other abuse.
- Organizations facing traffic from these networks may see near-term relief, while affected device owners still need remediation because a disruption does not itself establish that every endpoint is clean.
Second-order effects
- DDoS-defense providers and their customers can reassess exposure after the takedown, but attackers may seek replacement devices or shift activity to other botnet infrastructure.
- The action raises the value of coordination among law enforcement, network operators, and device owners: infrastructure disruption limits abuse only when compromised endpoints are also identified and secured.
Third-order effects
- If such operations are sustained, botnet operators face a less durable business model in which large device pools and their control infrastructure can be disrupted after being linked to high-impact attacks.
- The broader contest is likely to center on whether defenders can reduce the supply of insecure devices faster than attackers can rebuild botnets; the disclosed attack scale shows why mitigation capacity alone is not a complete solution.
The trend: Law enforcement and network defenders are increasingly pairing disruption of botnet infrastructure with large-scale DDoS mitigation as compromised-device networks become a central source of internet-scale attacks.