The AISURU botnet, also called Kimwolf, carried out a record-breaking distributed denial-of-service attack that peaked at 31.4 terabits per second. The attack lasted about 35 seconds and occurred in November 2025.Cloudflare’s automated systems detected and stopped the attack. The company reported this event as part of a larger pattern of extremely high-volume HTTP DDoS attacks during the final three months of 2025. These attacks represent a growing trend where threat actors launch very short but exceptionally powerful bursts of malicious traffic.

The same botnet also launched a campaign called “The Night Before Christmas” starting on December 19, 2025. During this operation, attacks averaged around 3 billion packets per second, 4 terabits per second, and 54 million requests per second. At their highest points, these attacks reached 9 billion packets per second, 24 terabits per second, and 205 million requests per second. These measurements demonstrate the botnet‘s capacity to flood targets with both massive packet volumes and overwhelming numbers of requests.

2025 DDos Attacks

DDoS attacks surged throughout 2025, increasing approximately 121% compared to the previous year. Automated defense systems handled an average of 5,376 attacks every hour, resulting in roughly 47.1 million total DDoS attacks recorded during the year.

Cloudflare specifically mitigated 34.4 million network-layer DDoS attacks in 2025, up from 11.4 million in 2024. During the fourth quarter alone, network-layer attacks accounted for 78% of all observed DDoS incidents. Overall attack volumes grew 31% compared to the previous quarter and 58% compared to 2024.

Hyper-volumetric attacks accelerated sharply in the fourth quarter of 2025, increasing 40% over the previous quarter from 1,304 incidents to 1,824. Earlier in the year, 717 such attacks occurred in the first quarter. Beyond the increasing frequency, attack sizes also grew dramatically, with peak volumes expanding more than seven times compared to large-scale attacks from late 2024.

The AISURU/Kimwolf botnet has infected over two million Android-based devices. A significant portion of these compromised devices are low-cost or unbranded Android television systems. Many infections function through residential proxy services, including networks like IPIDEA, which allow attackers to route malicious traffic through regular consumer internet connections.

Google recently took action against parts of the IPIDEA proxy network and filed legal proceedings against domains used for command-and-control operations and proxy traffic routing. Working together with Cloudflare, Google disrupted IPIDEA’s domain resolution systems, making it harder for operators to control infected devices and sell access to the proxy infrastructure. Cloudflare supported these efforts by suspending accounts and domains that misused its services to distribute malware and provide access to illegal residential proxy networks.

Research shows that IPIDEA used at least 600 trojanized Android applications containing proxy-related software development kits, along with more than 3,000 trojanized Windows programs disguised as legitimate software like OneDrive sync tools or Windows updates. Additionally, several VPN and proxy applications marketed by the company secretly turned Android devices into proxy exit nodes without users knowing or agreeing to it.

Further investigation revealed that operators ran numerous residential proxy services appearing to be independent businesses, but all relied on centralized backend infrastructure controlled by IPIDEA. Multiple proxy services that seemed unrelated were actually connected to this shared operational system.

During the fourth quarter of 2025, telecommunications companies, service providers, and carrier networks faced the most attacks, followed by information technology firms, gambling platforms, gaming services, and computer software providers. The most frequently targeted countries included China, Hong Kong, Germany, Brazil, the United States, the United Kingdom, Vietnam, Azerbaijan, India, and Singapore. Traffic analysis identified Bangladesh as the largest apparent source of DDoS traffic, surpassing Indonesia. Following Bangladesh were Ecuador, Indonesia, Argentina, Hong Kong, Ukraine, Vietnam, Taiwan, Singapore, and Peru.

Defense recommendations against packed malwareSecurity experts observe that DDoS operations continue expanding in both scale and complexity, exceeding previously known limits. This evolving threat landscape creates significant challenges for organizations trying to maintain effective defenses, especially those using traditional on-premises mitigation systems or limited scrubbing-center capacity. Organizations increasingly need to continuously reassess their mitigation strategies to address modern attack volumes and techniques.

References