Bottom line: Despite the international takedown of Kimwolf and Aisuru in March 2026, Aisuru’s server infrastructure has more than doubled within four months and over 20 successor botnets have adopted Kimwolf’s methods, because unpatched IoT and Android devices remain the actual root cause.
The international takedown of the Kimwolf and Aisuru botnets in March 2026 did not eliminate the threat but fragmented it: within four months, Aisuru’s infrastructure has more than doubled, and over 20 competing successor botnets have adopted Kimwolf’s approach.
In March 2026, authorities from the US, Canada and Germany, together with industry partners, dismantled the command-and-control server infrastructure of the Aisuru, Kimwolf, JackSkid and Mossad botnets and arrested a suspected Kimwolf operator from Canada. The networks had at times controlled more than three million devices worldwide and were linked to DDoS attacks of around 30 terabits per second. However, threat intelligence firm Censys notes in a recent report that the total infrastructure of known Aisuru servers has more than doubled within four months compared to the pre-takedown level. According to network equipment provider Arelion, as of July 2026 Aisuru once again accounts for around 33 percent of global DDoS attack traffic.
Kimwolf itself is, by consistent accounts, no longer active, but its technical approach has since been adopted by more than 20 competing botnet families. Nokia’s security team Deepfield, which was involved in the original takedown, describes the development as a hydra problem: cut off one head, and several new ones grow back. The number of daily active DDoS endpoints rose within a year from around one million to 8 to 9 million. Because the new botnets share the same pool of vulnerable devices and increasingly compete against one another, individual attacks are on average smaller: the median attack size is now around 20,000 to 30,000 IP addresses, compared to sometimes hundreds of thousands of nodes in earlier Kimwolf attacks.
For CISOs, the actual root cause is more relevant than the dismantling of individual groups: an almost inexhaustible number of unpatched, insecurely configured devices. Censys identified more than 117,000 internet-reachable systems on GPON fiber network access pages alone, many of which are still running with factory default settings. Kimwolf spread via an unusual route: instead of actively searching for vulnerabilities themselves, the operators rented access from residential proxy service providers and then compromised the participating devices via the openly accessible Android Debug Bridge service, which is enabled by default on numerous cheap, China-manufactured Android devices with unofficial, hidden proxy components.
Censys identifies three root causes for the problem: component manufacturers who ship simplified SDK components without security requirements, device manufacturers who fail to check these components for vulnerabilities along the manufacturing chain, and end users who ignore available security updates and continue operating discontinued legacy devices. According to Nokia, even after the originally exploited vulnerability is fixed, many affected home devices remain compromised, as third-party attackers have installed their own additional backdoors. Allyson Martinez, a security researcher at Censys, draws a sober conclusion: as long as these fundamental vulnerabilities remain unaddressed, Mirai and its successors are expected to remain a security threat for years to come.
Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.