Authorities Dismantle Mozi IoT Botnet Infrastructure After Record DDoS Attacks
Key Takeaways International law enforcement agencies have successfully dismantled the command-and-control (C2) infrastructure behind four major IoT botnets. The Aisuru, KimWolf, JackSkid, and Mossad...
Key Takeaways
- International law enforcement agencies have successfully dismantled the command-and-control (C2) infrastructure behind four major IoT botnets.
- The Aisuru, KimWolf, JackSkid, and Mossad botnets collectively infected over three million devices globally, launching DDoS attacks that peaked at an unprecedented 30 Terabits per second (Tbps).
- These botnets exploited vulnerabilities in IoT devices like DVRs, webcams, and enterprise WiFi routers, with some variants specifically targeting firewalled systems.
- The operation involved coordinated efforts from the U.S. Justice Department, German, and Canadian authorities, supported by a coalition of private cybersecurity firms.
Global Law Enforcement Cripples Massive IoT Botnet Operations
In a significant victory against cybercrime, an international coalition of law enforcement agencies has successfully dismantled the command-and-control (C2) infrastructure responsible for powering four colossal Internet of Things (IoT) botnets. This coordinated action targeted the operational backbone of the Aisuru, KimWolf, JackSkid, and Mossad botnet families.
Table Of Content
Unprecedented Scale of Attack and Infection
These sophisticated malicious networks had amassed a formidable army of over three million compromised devices worldwide. Leveraging this vast network, the botnets unleashed devastating Distributed Denial of Service (DDoS) attacks, some reaching an astonishing peak of 30 Terabits per second (Tbps). This represents an unprecedented volume of malicious traffic, capable of crippling even robust online services.
The primary targets for infection included a range of vulnerable IoT infrastructure, such as digital video recorders, web cameras, and enterprise WiFi routers. Threat actors exploited default security weaknesses and known vulnerabilities to enlist these devices into their botnet. Notably, the operators behind the KimWolf and JackSkid botnets exhibited advanced capabilities, specifically compromising devices typically considered isolated behind network firewalls.
Cybercrime-as-a-Service and Targeted Attacks
Once compromised, these devices became part of a large-scale “cybercrime-as-a-service” platform. The botnet administrators monetized their illicit infrastructure by leasing access to other threat actors, enabling them to launch highly disruptive volumetric and application-layer DDoS attacks. These attacks indiscriminately targeted servers across the globe, including critical infrastructure and IP addresses belonging to the Department of Defense Information Network (DoDIN).
| Botnet Family | Attack Commands Issued | Primary Target Focus |
|---|---|---|
| Aisuru | > 200,000 | Global infrastructure and servers |
| JackSkid | > 90,000 | Firewalled IoT devices |
| KimWolf | > 25,000 | Firewalled IoT devices |
| Mossad | > 1,000 | General IoT devices |
The immense capacity of these combined botnets facilitated hundreds of thousands of coordinated cyber campaigns. Victims of the record-breaking 30 Tbps attacks often faced severe operational downtime, incurring tens of thousands of dollars in remediation costs and direct financial losses. In numerous cases, the cybercriminals used this overwhelming attack capability as an extortion tool, demanding payments to cease the malicious traffic. As of March 2026, hundreds of thousands of the three million globally infected devices were located within the United States.
Coordinated International Takedown
The operational takedown focused on strategically severing the communication links between the compromised IoT endpoints and the threat actors’ C2 architecture. The Defense Criminal Investigative Service (DCIS), with support from the FBI Anchorage Field Office, executed multiple seizure warrants targeting U.S.-registered internet domains, virtual servers, and other cyber infrastructure used by the botnet operators. Simultaneously, Germany’s Bundeskriminalamt (BKA) and Canada’s Royal Canadian Mounted Police (RCMP) conducted legal actions and apprehensions to disable the individuals operating these networks.
This successful operation highlights the crucial role of public-private partnerships and threat intelligence sharing in combating sophisticated cyber threats. Law enforcement agencies received invaluable assistance from a broad coalition of technology and security firms, including Akamai, Amazon Web Services, Cloudflare, The Shadowserver Foundation, and Team Cymru. This collaborative intelligence effort enabled authorities to meticulously map the extensive C2 networks, leading to a synchronized disruption that severely limited the operators’ ability to issue further attack commands and prevented future infections.
What You Should Do
- Patch and Update: Ensure all IoT devices, including routers, cameras, and DVRs, are running the latest firmware and software updates to mitigate known vulnerabilities.
- Change Default Credentials: Immediately change default usernames and passwords on all IoT devices to strong, unique credentials.
- Network Segmentation: Implement network segmentation to isolate IoT devices from critical business networks, limiting potential lateral movement in case of a compromise.
- Implement DDoS Protection: Employ robust DDoS mitigation solutions from reputable providers to protect against volumetric and application-layer attacks.
- Monitor Network Traffic: Continuously monitor network traffic for unusual patterns or spikes that could indicate a botnet infection or DDoS attack.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.