Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Exim Mail Server Vulnerabilities Lead to Crash via DNS Data
May 2, 2026
AiTM Phishing Attacks Target SharePoint, HubSpot, Google
May 2, 2026
Attackers Abuse AppSheet, Netlify, Telegram for Google Facebook
May 2, 2026
Home/Threats/Mirai Botnets Evolve: Massive DDoS Mirai-Based Into
Threats

Mirai Botnets Evolve: Massive DDoS Mirai-Based Into

The internet has experienced a sharp rise in botnet-driven threats over the past year, with much of this activity stemming from Mirai. This malware family, considered one of the most influential in...

Sarah simpson
Sarah simpson
March 25, 2026 3 Min Read
0 0

The internet has experienced a sharp rise in botnet-driven threats over the past year, with much of this activity stemming from Mirai. This malware family, considered one of the most influential in modern history, continues to evolve significantly. A

Top locations for botnet C2 servers (Source - Pulsedive)
Top locations for botnet C2 servers (Source – Pulsedive)

Pulsedive researchers identified and tracked several active Mirai-based botnets, with Aisuru and Kimwolf emerging as the most destructive.

Together, these two variants — often referred to as Aisuru-Kimwolf — have compromised between one and four million hosts around the world.

Cloudflare documented that Aisuru-Kimwolf is behind some of the largest DDoS attacks ever recorded, including a 31.4 terabit-per-second flood and a 14.1 billion packet-per-second assault.

These numbers go well beyond anything earlier Mirai variants could produce and highlight just how dangerous the next generation of these botnets has become.

The many variants of Mirai (Source - Pulsedive)
The many variants of Mirai (Source – Pulsedive)

The operators behind Aisuru-Kimwolf have turned their infrastructure into a criminal business, selling access to compromised devices through platforms like Discord and Telegram.

On March 19, 2026, the U.S. Department of Justice announced court-authorized disruption actions against the C2 servers supporting Aisuru, KimWolf, JackSkid, and Mossad botnets, with enforcement operations spanning Canada and Germany.

Beyond DDoS attacks, the botnets have been used to abuse residential proxy networks, routing attack traffic through IP addresses belonging to ordinary homeowners, making the activity far harder to trace. Despite the takedown efforts, these botnets continue to adapt and find new ways to stay operational.

Kimwolf’s Infection Mechanism and Infrastructure Evasion

Kimwolf is an Android-focused subvariant of Aisuru built to target mobile devices and Smart TVs.

It has infected approximately two million Android devices globally, leveraging the same DDoS capabilities as Aisuru but modified to work on Android systems.

Once a vulnerable device is reached, Kimwolf runs an install script that downloads .apk files from an attacker-controlled server. The script makes each file executable and runs them in sequence, targeting different CPU architectures to infect as many devices as possible.

Distribution of KimWolf IP addresses (Source - Pulsedive)
Distribution of KimWolf IP addresses (Source – Pulsedive)

After Google and the DOJ disrupted the IPIDEA residential proxy infrastructure tied to Kimwolf, reports surfaced that the botnet had shifted to The Invisible Project (I2P), a decentralized, encrypted communications network designed to anonymize traffic.

This shift was a direct response to takedown pressure — I2P is far harder to monitor or shut down than conventional infrastructure.

The move underlines a clear pattern: these operators watch law enforcement actions closely and quickly reroute their operations the moment any disruption hits.

How KimWolf abuses residential proxy infrastructure (Source - Pulsedive)
How KimWolf abuses residential proxy infrastructure (Source – Pulsedive)

Network providers often offer DDoS protection solutions that can detect and block bot-driven traffic, and organizations should take full advantage of these.

Protective DNS services can filter suspicious domain queries before they reach internal systems. Publicly accessible network devices, especially routers, should be patched consistently.

Default credentials on all networking equipment must be replaced with strong, unique passwords during initial setup and should never be left unchanged.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarePatchSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Open Directory Malware Campaign Delivers RAT via Obfuscated

Next Post

Ghost SPN Attack Enables Stealthy Kerberoasting by

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Spyware Platform: Rebrand & Resell Android Lets Buyers
May 1, 2026
Attackers Abuse CAPTCHA, ClickFix for Cred Tactics Boost
May 1, 2026
DDoS Malware Exploits Jenkins to Attack Source Engine Games
May 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Sarah simpson
Sarah simpson
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us