Dozens of new botnets are rising from the ashes of Kimwolf and Aisuru
Your old router might have already changed several operators.

A LAN cable is plugged into the DSL slot of a WLAN router. Fabian Sommer/picture alliance/Getty.
- After March's takedown, Aisuru's infrastructure doubled within four months and now drives about 33% of global DDoS traffic.
- Kimwolf is inactive, but its blueprint spawned more than 20 rival botnets as daily attack endpoints reached 8–9 million.
- Competition for vulnerable devices has reduced typical attacks to 20,000–30,000 addresses, down from hundreds of thousands under Kimwolf.
- Poorly secured routers, cameras and Android devices let botnets rebuild, while manufacturers, producers and users leave flaws unresolved.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Security researchers are warning of rapidly regenerating DDoS infrastructure. Following the disruption of the largest botnets the world has ever seen, Kimwolf and Aisuru, dozens of other botnets have spawned, competing for the same pool of vulnerable devices.
Last year, terabit-per-second (Tbps)-scale distributed denial of service (DDoS) attacks became the new normal, and Cloudflare reported the largest-ever DDoS at 29.7 Tbps, attributed to the Aisuru botnet.
Aisuru commanded 1-4 million compromised devices globally, and was accompanied by KimWolf, another massive botnet that compromised 2 million Android devices and briefly surpassed Google’s traffic on the website leaderboard.
A major takedown operation disrupted both botnets in March this year, and a Canadian man suspected of operating KimWolf was arrested.
But this didn’t eliminate the main issue: a massive pool of vulnerable devices globally.
“Although the takedown produced an immediate reduction in active Aisuru C2 servers, within 4 months, the total infrastructure of known Aisuru servers had more than doubled relative to its pre-takedown size,” said Censys, a threat intelligence platform, in a new report.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Aisuru “now drives approximately 33% of global DDoS attack traffic,” according to a report by Arelio, released in July 2026.
Meanwhile, Kimwolf metastasized into more than 20 competing botnets. Nokia’s Deepfield team warns that the residential proxy problem is getting bigger, not smaller, comparing it to the hydra problem – cutting off one head produces several new ones.
“The number of DDoS active daily endpoints climbed from roughly 1 million to 8–9 million over the last year,” concludes the firm that helped to take down Kimwolf.
While the disruption achieved the real impact – Kimwolf is no longer active – its blueprint was quickly adopted by other botnet families. They now compete fiercely for the same pool of vulnerable devices.
This means that individual attacks are smaller – median attack sizes reach roughly 20,000-30,000 IPs, compared to hundreds of thousands of nodes observed in previous Kimwolf attacks.
Vulnerable devices aren’t going away
The Mirai botnet, originally developed a decade ago, established a methodology of scanning the internet for vulnerable devices with default credentials and exploiting them at scale. Its creators were sentenced after the source code was leaked. Dozens of Mirai variants still rank as a major DDoS threat.
Aisuru targets poorly secured routers, CCTV systems, Android TV boxes, and other IoT devices that have factory-set credentials and unpatched vulnerabilities.
“So long as the botnet has access to a pool of unpatched devices to recruit, it will continue to be a public threat. If the exploitable vulnerabilities that built a botnet in the first place are never addressed at the source, its infrastructure may regenerate, and potentially exceed, its original size once enforcement pressure lifts,” Censys warns in the report.
Censys search engine identifies over 117,000 exposed login pages for Gigabit Passive Optical Network (GPON) networks, which deliver gigabit internet service. A high number of default HTML titles suggests that many of them might be left with factory-default settings.
Check if your data has been leaked
Kimwolf’s primary means of spreading is one of the most ingenious in botnet history. Rather than scanning the internet for vulnerable devices, its operators rented access to residential proxy services and then compromised their participant devices via the exposed Android Debug Bridge service.
Many cheap Android devices produced in China often include unofficial apps littered with proxy SDKs, designed to sell users’ internet connection without their knowledge, and have ADB mode enabled by default. Kimwolf hijacks proxy access and infects devices on home networks that wouldn’t be otherwise accessible.
“The residential proxy problem is not going away. While some proxy providers patched the ADB bug, most of the compromised home endpoints remain compromised, with third-party attackers having installed their own backdoors,” Nokia’s team said.
The researchers don’t expect the pool of proxy endpoints to ever dry up, because the industry is fueled by multi-billion-dollar incentives. Censys added that 90% of exposed ADB services run on default ports.
Censys identifies 3 streams of vulnerable devices: component manufacturers who ship simplified SDK components with no security caveats, producers who fail to audit for these security flaws throughout the assembly line, and unknowing users who disregard security updates and continue using end-of-life devices.
“Until these foundational weak points are remediated, it’s likely that Mirai and its heirs will remain a security threat for years to come,“ Allyson Martinez, a security researcher at Censys, concludes.