← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
IOC - The Strongest Ever? Unveiling the Inside Story of the 11.5T Ultra-Large Botnet AISURU (pulse by celestre)
Since 2025, global DDoS attack bandwidth peaks have continuously broken historical records, soaring from 3.12 Tbps at the beginning of the year to a staggering 11.5 Tbps recently. A botnet called AISURU has been observed operating behind numerous high-impact or record-breaking attacks. The AISURU botnet was first disclosed by XLab in August 2024 and was involved in DDoS attacks targeting the distribution platform of "Black Myth: Wukong." Since March of this year, XLab's large-scale threat monitoring platform has continuously captured new samples of this botnet. Multiple sources indicate that the group behind it allegedly compromised a router firmware upgrade server in April and expanded the botnet by distributing malicious scripts. The current number of nodes is reportedly 300,000. (by celestre)
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
AS206509|KCOM
Indicators of Compromise (4 / 22 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 1f4eccfecef1ddf7c35d2f55c70550ee | MD5 of 616a3bef8b0be85a3c2bc01bbb5fb4a5f98bf707 | 2025-09-18 | |
| FileHash-MD5 | 4e8ca1efff2e4b79fb7db95d3971caaa | MD5 of 26e9e38ec51d5a31a892e57908cb9727ab60cf88 | 2025-09-18 | |
| FileHash-MD5 | 5b1b228bb0d1ebf3ef477141013b7a86 | MD5 of 053a0abe0600d16a91b822eb538987bca3f3ab55 | 2025-09-18 | |
| FileHash-MD5 | 72616e99230dab898ba193741a0b5d35 | MD5 of 08e9620a1b36678fe8406d1a231a436a752f5a5e | 2025-09-18 |