DDos outage attack
– Getty Images

Another record-breaking distributed denial of service (DDoS) attack by a notorious monster in the space has been thwarted.

The culprit was Aisuru, a Turbo Mirai-class botnet that targets Internet of Things (IoT) flaws, mainly in the form of home routers and cameras. According to Cloudflare, the web giant stopped an Aisuru attack paired with fellow killer botnet Kimwolf that peaked at 31.4 Tb/s and 200 million requests per second.

Dubbed as the apex of botnets by Cloudflare, Aisuru was behind what Microsoft last year dubbed the largest DDoS attack ever observed in the cloud. The hyperscaler thwarted the exploit, which measured at 15.72 Tb/s (terabits per second) and 3.64 billion packets per second (Bpps).

In its latest heavy-hitting attempt dubbed “The Nightmare Before Christmas” by Cloudflare, the December 19 campaign targeted both Cloudflare customers and Cloudflare’s dashboard and infrastructure with hyper-volumetric HTTP DDoS attacks surpassing rates of 200 million requests per second alongside Layer 4 DDoS attacks peaking at 31.4 Tb/s.

Over half of the attacks in the Aisuru DDoS campaign lasted between one and two minutes, with only 6% persisting beyond that. The majority (90%) reached peak volumes of 1–5 Tb/s, and about 94% generated between 1 and 5 billion packets per second, with Cloudflare detecting and mitigating each attempt automatically before any internal alerts could be triggered.

In contrast to its usual compromise of IoT devices and routers, the holiday-season attack targeted Android-based Smart TVs.

Aisuru, DDozilla

According to its Q3 DDoS report released in December, Cloudflare mitigated 2,867 Aisuru attacks across 2025, with 1,304 hyper-volumetric attacks in the last quarter at an increase of 54% quarter-over-quarter (QoQ).

The botnet unleashed hyper-volumetric DDoS attacks routinely surpassing 1Tb/s and one billion packets per second. The number of these attacks jumped 54% QoQ, averaging 14 hyper-volumetric attacks daily, with attacks peaking at its previous record-breaker of 29.7 Tb/s and 14.1 Bpps.

The botnet was used to target sectors such as hosting providers and telecommunication providers, with its dominance increased by distributors offering “chunks” of Aisuru as botnets-for-hire.

Lasting just 69 seconds, the previous peak Aisuru attack detected and stopped by Cloudflare was a user datagram protocol (UDP) carpet-bombing attack targeting an average of 15K destination ports per second, randomizing various packet attributes in an effort to evade defenses.

Cloudflare detected 8.3 million DDoS attacks in the last quarter overall, reflecting a 40% year-over-year (YoY) increase in threats to networks, and leading it to declare DDoS attacks as a commonplace threat to the internet.

UDP DDoS attacks such as Aisuru’s saw a 231% increase QoQ to become the top attack vector at the network-layer in Q4 2025, ahead of DNS floods in Cloudflare’s research.