{"id":11481,"date":"2026-03-20T10:03:37","date_gmt":"2026-03-20T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/20\/authorities-disrupt-iot-botnet-infrastructure-behind-record-breaking-30-tbps-ddos-attacks\/"},"modified":"2026-03-20T10:03:37","modified_gmt":"2026-03-20T10:03:37","slug":"authorities-disrupt-iot-botnet-infrastructure-behind-record-breaking-30-tbps-ddos-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/20\/authorities-disrupt-iot-botnet-infrastructure-behind-record-breaking-30-tbps-ddos-attacks\/","title":{"rendered":"Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks"},"content":{"rendered":"<p>    Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Authorities have successfully dismantled the command-and-control (C2) infrastructure powering four massive Internet of Things (IoT) botnets.<\/p>\n<p>The U.S. Justice Department, collaborating closely with Canadian and German agencies, targeted the administrators and architecture behind the <a href=\"https:\/\/cybersecuritynews.com\/31-4-tbps-ddos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Aisuru<\/a>, KimWolf, JackSkid, and Mossad botnets.<\/p>\n<p>Together, these malicious networks infected over three million devices globally and launched catastrophic Distributed Denial of Service (DDoS) attacks, with peak volumetric traffic reaching an unprecedented 30 Terabits per second (Tbps).<\/p>\n<p>The botnets primarily weaponized vulnerable IoT infrastructure, including digital video recorders, web cameras, and enterprise WiFi routers. The threat actors built an expansive botnet army by exploiting poor default security postures and known vulnerabilities.<\/p>\n<p>Notably, the operators behind the KimWolf and JackSkid botnets demonstrated sophisticated evasion capabilities, specifically targeting and infecting devices that were traditionally isolated and positioned behind network firewalls.<\/p>\n<p>Once compromised, these devices were enslaved into a massive \u201ccybercrime-as-a-service\u201d platform. The administrators monetized their illicit infrastructure by leasing access to other threat actors, effectively democratizing the ability to launch highly disruptive volumetric and <a href=\"https:\/\/cybersecuritynews.com\/why-ddos-attacks-are-still-a-major-threat-in-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">application-layer DDoS attacks<\/a>.<\/p>\n<p>These attacks targeted servers worldwide, notably including critical infrastructure and IP addresses owned by the Department of Defense Information Network (DoDIN).<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Botnet Family<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Attack Commands Issued<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Primary Target Focus<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Aisuru<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">&gt; 200,000<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Global infrastructure and servers<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>JackSkid<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">&gt; 90,000<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Firewalled IoT devices<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>KimWolf<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">&gt; 25,000<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Firewalled IoT devices<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Mossad<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">&gt; 1,000<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">General IoT devices<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>The sheer scale of the combined botnets allowed threat actors to launch hundreds of thousands of coordinated campaigns. Victims facing these <a href=\"https:\/\/cybersecuritynews.com\/29-7-tbps-ddos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">record-breaking 30 Tbps attacks<\/a> experienced severe operational downtime, resulting in tens of thousands of dollars in remediation costs and direct financial losses.<\/p>\n<p>In many instances, the cybercriminals leveraged this overwhelming attack capacity as a coercive tool, demanding extortion payments from targeted organizations to halt the malicious traffic flow. As of March 2026, hundreds of thousands of the three million globally infected devices were located within the United States.<\/p>\n<p>The operational takedown focused on surgically severing the communication channels between the infected IoT endpoints and the threat actors\u2019 C2 architecture.<\/p>\n<p>The Defense Criminal Investigative Service (DCIS), supported by the FBI Anchorage Field Office, executed numerous seizure warrants targeting U.S.-registered internet domains, virtual servers, and related cyber infrastructure utilized by the botnet operators.<\/p>\n<p>Simultaneous legal actions and target apprehensions were conducted by Germany\u2019s Bundeskriminalamt (BKA) and Canada\u2019s Royal Canadian Mounted Police (RCMP) to disable the individuals operating the networks.<\/p>\n<p>This operation underscores the critical necessity of public-private threat intelligence sharing in the modern security landscape. Law enforcement agencies were supported by a vast coalition of technology and security firms, including Akamai, Amazon Web Services, Cloudflare, The Shadowserver Foundation, and Team Cymru.<\/p>\n<p>This collective intelligence allowed authorities to map the vast C2 networks and execute a coordinated disruption, severely limiting the operators\u2019 ability to issue further attack commands and preventing future infections.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/authorities-disrupts-iot-botnet\/\">Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/authorities-disrupts-iot-botnet\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks Authorities have successfully dismantled the command-and-control (C2) infrastructure powering four massive Internet of Things (IoT) botnets. The U.S. Justice Department, collaborating closely with Canadian and German agencies, targeted the administrators and architecture behind the Aisuru, KimWolf, JackSkid, and Mossad botnets. Together, these malicious networks [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-11481","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11481"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11481"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11481\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}