Cybercrime

Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbps

Cloudflare recently mitigated a new record-breaking Aisuru attack that peaked at 14.1 Bpps.

Proxy disrupted

The Aisuru botnet continues to be responsible for record-breaking distributed denial-of-service (DDoS) attacks, web performance and security firm Cloudflare reported this week. 

A new record DDoS attack was mitigated by Cloudflare in the third quarter of 2025. The attack peaked at 29.7 terabits per second (Tbps) and 14.1 billion packets per second (Bpps).

“The 29.7 Tbps was a UDP carpet-bombing attack bombarding an average of 15K destination ports per second. The distributed attack randomized various packet attributes in an attempt to evade defenses,” Cloudflare explained. 

The previous record, also attributed to Aisuru, peaked at 22.2 Tbps and 10.6 Bpps.

Aisuru, dubbed a TurboMirai-class IoT botnet, has been responsible for many hyper-volumetric DDoS attacks. 

Powered by compromised devices such as routers, CCTV cameras, and DVR systems, the botnet is offered under a DDoS-for-hire model. Customers can also use the botnet for residential proxy services, which can be useful for spamming, scraping, and credential stuffing.

Cloudflare this year mitigated nearly 3,000 Aisuru attacks, including more than 1,300 in Q3 2025. 

Advertisement. Scroll to continue reading.

Aisuru is also responsible for the largest ever DDoS attack on Microsoft’s Azure cloud service, peaking at over 15.7 Tbps and 3.6 Bpps. The attack was aimed at a single endpoint in Australia.

DDoS attacks powered by the botnet are often aimed at hosting providers, gaming companies, telecoms firms, and financial services. 

Related: Cloudflare Outage Not Caused by Cyberattack

Related: ShadowV2 DDoS Service Lets Customers Self-Manage Attacks

Related: Arch Linux Project Responding to Week-Long DDoS Attack

Related Content

Cybercrime

Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy...

Malware & Threats

Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.

Cybercrime

Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.

Artificial Intelligence

The company topped revenue and earnings forecasts for the first quarter of 2026, but its shares plunged more than 20%.

Cybercrime

The DDoS attack caused a major outage, but Mastodon mitigated it within a few hours.

Malware & Threats

The exploitation of the command injection vulnerability started one year after public disclosure and PoC exploit code publication.

Cybercrime

A pro-Iran hacker group has taken credit for the attack on Bluesky, which appears to have lasted 24 hours. 

Cybercrime

Authorities in 21 countries participated in a coordinated action against DDoS-for-hire services.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version