Skip to content
Dozens of new botnets are rising from the ashes of Kimwolf and Aisuru

Dozens of new botnets are rising from the ashes of Kimwolf and Aisuru

Cybernews August 11, 2026

Security researchers are warning of rapidly regenerating DDoS infrastructure. Following the disruption of the largest botnets the world has ever seen, Kimwolf and Aisuru, dozens of other botnets have spawned, competing for the same pool of vulnerable devices.

Last year, terabit-per-second (Tbps)-scale distributed denial of service (DDoS) attacks became the new normal, and Cloudflare reported the largest-ever DDoS at 29.7 Tbps, attributed to the Aisuru botnet.

Aisuru commanded 1-4 million compromised devices globally, and was accompanied by KimWolf, another massive botnet that compromised 2 million Android devices and briefly surpassed Google’s traffic on the website leaderboard.

A major takedown operation disrupted both botnets in March this year, and a Canadian man suspected of operating KimWolf was arrested.

But this didn’t eliminate the main issue: a massive pool of vulnerable devices globally.

“Although the takedown produced an immediate reduction in active Aisuru C2 servers, within 4 months, the total infrastructure of known Aisuru servers had more than doubled relative to its pre-takedown size,” said Censys, a threat intelligence platform, in a new report .

Aisuru “now drives approximately 33% of global DDoS attack traffic,” according to a report by Arelio, released in July 2026.

Meanwhile, Kimwolf metastasized into more than 20 competing botnets. Nokia’s Deepfield team warns that the residential proxy problem is getting bigger, not smaller , comparing it to the hydra problem – cutting off one head produces several new ones.

“The number of DDoS active daily endpoints climbed from roughly 1 million to 8–9 million over the last year,” concludes the firm that helped to take down Kimwolf.

While the disruption achieved the real impact – Kimwolf is no longer active – its blueprint was quickly adopted by other botnet families. They now compete fiercely for the same pool of vulnerable devices.

This means that individual attacks are smaller – median attack sizes reach roughly 20,000-30,000 IPs, compared to hundreds of thousands of nodes observed in Kimwolf attacks.

The Mirai botnet, originally developed a decade ago, established a methodology of scanning the internet for vulnerable devices with default credentials and exploiting them at scale. Its creators were sentenced after the source code was leaked. Dozens of Mirai variants still rank as a major DDoS threat.

Aisuru targets poorly secured routers, CCTV systems, Android TV boxes, and other IoT devices that have factory-set credentials and unpatched vulnerabilities.

“So long as the botnet has access to a pool of unpatched devices to recruit, it will continue to be a public threat. If the exploitable vulnerabilities that built a botnet in the first place are never addressed at the source, its infrastructure may regenerate, and potentially exceed, its original size once enforcement pressure lifts,” Censys warns in the report.

Censys engine identifies over 117,000 exposed login pages for Gigabit Passive Optical Network (GPON) networks, which deliver gigabit internet service. A high number of default HTML titles suggests that many of them might be left with factory-default settings.

Kimwolf’s primary means of spreading is one of the most ingenious in botnet history. Rather than scanning the internet for vulnerable devices, its operators rented access to residential proxy services and then compromised their participant devices via the exposed Android Debug Bridge service.

Many cheap Android devices produced in China often include unofficial apps littered with proxy SDKs, designed to sell users’ internet connection without their knowledge, and have ADB mode enabled by default. Kimwolf hijacks proxy access and infects devices on networks that wouldn’t be otherwise accessible.

“The residential proxy problem is not going away. While some proxy providers patched the ADB bug, most of the compromised endpoints remain compromised, with third-party attackers having installed their own backdoors,” Nokia’s team said.

The researchers don’t expect the pool of proxy endpoints to ever dry up, because the industry is fueled by multi-billion-dollar incentives. Censys added that 90% of exposed ADB services run on default ports.

Censys identifies 3 streams of vulnerable devices: component manufacturers who ship simplified SDK components with no security caveats, producers who fail to audit for these security flaws throughout the assembly line, and unknowing users who disregard security updates and continue using end-of-life devices.

“Until these foundational weak points are remediated, it’s likely that Mirai and its heirs will remain a security threat for years to come,“ Allyson Martinez, a security researcher at Censys, concludes.

Extracted Entities