/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A US DOJ operation disrupted four botnets that infected 3M+ devices and includes the Aisuru and Kimwolf botnets used in a 31.4 Tbps DDoS attack in November 2025

Wired Andy Greenberg

Context & Ripple Effects

The operation follows a previously disclosed 31.4 Tbps attack attributed to Aisuru and Kimwolf, linking an unusually large DDoS event to a broader infected-device network. It also extends a DOJ pattern that includes the DanaBot charges and an earlier RSocks disruption, targeting botnet infrastructure rather than only individual attacks.

First-order effects

  • Aisuru, Kimwolf, and two other disrupted botnets lose operational continuity, reducing the immediate pool of more than 3 million compromised devices available for DDoS or other abuse.
  • Organizations facing traffic from these networks may see near-term relief, while affected device owners still need remediation because a disruption does not itself establish that every endpoint is clean.

Second-order effects

  • DDoS-defense providers and their customers can reassess exposure after the takedown, but attackers may seek replacement devices or shift activity to other botnet infrastructure.
  • The action raises the value of coordination among law enforcement, network operators, and device owners: infrastructure disruption limits abuse only when compromised endpoints are also identified and secured.

Third-order effects

  • If such operations are sustained, botnet operators face a less durable business model in which large device pools and their control infrastructure can be disrupted after being linked to high-impact attacks.
  • The broader contest is likely to center on whether defenders can reduce the supply of insecure devices faster than attackers can rebuild botnets; the disclosed attack scale shows why mitigation capacity alone is not a complete solution.

The trend: Law enforcement and network defenders are increasingly pairing disruption of botnet infrastructure with large-scale DDoS mitigation as compromised-device networks become a central source of internet-scale attacks.

Discussion

  • @zephyr_z9 @zephyr_z9 on x
    Old man Wally was with Jensen 2-3 days ago LMAO [image]
  • @zephyr_z9 @zephyr_z9 on x
    Old man has a net worth of $500M Got caught swapping serial numbers using a fucking hair dryer [image]
  • @mattjay Matt Johansen on x
    DOJ just announced takedown of four major botnets - Aisuru, KimWolf, JackSkid, and Mossad. This is significant scale. > The numbers here are wild: combined 3+ million infected devices globally (hundreds of thousands in US alone), and attacks hitting 30 Tbps. That's [image]
  • @ericjgeller.com Eric Geller on bluesky
    The U.S. has seized web infrastructure that cybercriminals were using to run four major DDoS botnets powered largely by hacked IoT devices.  The botnets conducted record-breaking and costly attacks.  Canada and Germany appear to have arrested some of the operators. www.justice.go…
  • @agreenberg Andy Greenberg on bluesky
    Feds just took down 4 botnets, including the Aisuru and Kimwolf botnets that carried out record-breaking DDOS attacks peaking at 30+ terabits per second, nearly three times the previous record.  DOJ says the botnets had hijacked more than three million devices. www.wired.com/stor…
  • r/technews r on reddit
    Aisuru - Largest botnet in the world, taken down in joint operation between Canadian, German, and American federal police.
  • r/blackhat r on reddit
    US Takes Down Botnets Used in Record-Breaking Cyberattacks