PULSE NAME
Aisuru botnet: Early October attacks escalate into record-setting DDoS activity
WHITE Aisuru PetrP.73 2025-12-21 Modified: 2026-01-20
44
IOCs
MEDIUM VOLUME
The Aisuru botnet, a notably advanced Internet of Things (IoT)-based threat, has rapidly expanded to approximately 500,000 compromised devices, doubling in size within a month. The botnet employs a multifaceted infection strategy, which may include a firmware supply-chain compromise, to grow its network. By late October 2025, Aisuru had executed one of the largest and most sustained DDoS (Distributed Denial of Service) attacks on record, detected by Cloudflare. The attack involved a diverse array of devices, such as routers, DVRs, internet-connected cameras, and firewall appliances. Cloudflare's analysis highlights a significant surge in hyper-volumetric DDoS attacks, primarily characterized by UDP (User Datagram Protocol) flood techniques. The DDoS attack record escalated dramatically from 4.2 Tbps in October 2024 to an unprecedented 29.7 Tbps just a year later-a staggering increase of 707%.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Aisuru
Indicators of Compromise (5 / 44 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 053a0abe0600d16a91b822eb538987bca3f3ab55 SHA1 of 08717d85a8a296279c2d2b792a33714d216a9de1950173d603222f78da9b9ca5 2025-12-21
FileHash-SHA1 08e9620a1b36678fe8406d1a231a436a752f5a5e SHA1 of 7a5a5c813d636d96906fb4bf8f76c7f296a467dca756e92450f32dc69d781b71 2025-12-21
FileHash-SHA1 09894c3414b42addbf12527b0842ee7011e70cfd SHA1 of 90e3b997161e33c6485b48182073a864dd3d0775ab96cadbf1b7c9dd4821c6d1 2025-12-21
FileHash-SHA1 26e9e38ec51d5a31a892e57908cb9727ab60cf88 SHA1 of 201d872e05f45062f3b18f1cb2bca7d5fe3811e7e6d4b8616d565a011fba091d 2025-12-21
FileHash-SHA1 616a3bef8b0be85a3c2bc01bbb5fb4a5f98bf707 SHA1 of 50d3806f47d3f701d5f1f93bf39f827f936e3d1f43fa2cd8408db9655d53fb83 2025-12-21