Quick Summary
The Securityish Brief
The AISURU/Kimwolf botnet has been linked to a record-setting DDoS attack that peaked at 31.4 Tbps and lasted for only 35 seconds in November 2025. Cloudflare, which detected and mitigated the attack, noted that this incident is part of a broader trend of hyper-volumetric DDoS attacks that have increased significantly in the last year. In 2025, DDoS attacks surged by 121%, with Cloudflare mitigating an average of 5,376 attacks every hour.
During the fourth quarter of 2025, the botnet was also involved in another campaign called The Night Before Christmas, which began on December 19, 2025. This campaign recorded average attack sizes of 4 Tbps, with maximum rates reaching up to 24 Tbps. The alarming increase in DDoS attacks, particularly hyper-volumetric ones, indicates a growing threat landscape.
Cloudflare reported that the number of network-layer DDoS attacks rose to 34.4 million in 2025, compared to 11.4 million in 2024. The fourth quarter alone saw a 31% increase in attacks compared to the previous quarter, highlighting the escalating nature of these threats.
AISURU/Kimwolf has compromised over 2 million Android devices, primarily off-brand Android TVs, by exploiting residential proxy networks like IPIDEA. Google has taken steps to disrupt IPIDEA, which has been linked to the enrollment of devices through at least 600 trojanized Android apps and over 3,000 trojanized Windows binaries.
Cloudflare’s report also noted that telecommunications and service providers were the most attacked sectors, with countries like China, Hong Kong, and the U.S. being heavily targeted. The rise in DDoS attacks has raised concerns about the effectiveness of traditional mitigation strategies, prompting organizations to reassess their defense mechanisms.
Understanding the Threat Landscape
The rapid increase in DDoS attacks, particularly those executed by sophisticated botnets like AISURU/Kimwolf, reveals a significant challenge for organizations. The complexity and scale of these attacks necessitate a reevaluation of existing security measures, especially for those relying on outdated mitigation strategies.
Organizations must remain vigilant and proactive in monitoring their networks for unusual activity. The growing trend of using compromised devices, such as Android TVs, as part of botnets underscores the importance of securing all endpoints within an organization.
Key Takeaways
- Regularly update all devices and software to protect against vulnerabilities that could be exploited by botnets.
- Implement robust network monitoring to detect unusual traffic patterns indicative of DDoS attacks.
- Consider advanced DDoS mitigation services to enhance your organization’s defense against large-scale attacks.
- Educate employees about the risks of downloading unverified applications that may compromise devices.
- Review and strengthen your incident response plan to ensure quick action during a DDoS attack.
Key Terms & Concepts
- DDoS Attack: In this article, a DDoS attack refers to a malicious attempt to disrupt the normal functioning of a targeted server, service, or network by overwhelming it with a flood of traffic.
- Botnet: A botnet is a network of compromised devices that are controlled by an attacker to perform automated tasks, such as launching DDoS attacks.
- Hyper-Volumetric Attack: In this context, a hyper-volumetric attack refers to a type of DDoS attack characterized by extremely high traffic volumes, often exceeding several terabits per second.
- IPIDEA: IPIDEA is a proxy network linked to the AISURU/Kimwolf botnet, which has been used to control compromised devices and facilitate DDoS attacks.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.