{"id":6948,"date":"2025-09-16T10:03:37","date_gmt":"2025-09-16T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/16\/aisuru-botnet-with-300000-hijacked-routers-behind-the-recent-massive-11-5-tbps-ddos-attack\/"},"modified":"2025-09-16T10:03:37","modified_gmt":"2025-09-16T10:03:37","slug":"aisuru-botnet-with-300000-hijacked-routers-behind-the-recent-massive-11-5-tbps-ddos-attack","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/16\/aisuru-botnet-with-300000-hijacked-routers-behind-the-recent-massive-11-5-tbps-ddos-attack\/","title":{"rendered":"AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack"},"content":{"rendered":"<p>    AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Since early 2025, the cybersecurity community has witnessed an unprecedented surge in distributed denial-of-service (DDoS) bandwidth, culminating in a record-shattering 11.5 Tbps assault attributed to a botnet named AISURU.<\/p>\n<p>Emerging from XLab\u2019s continuous monitoring of global <a href=\"https:\/\/cybersecuritynews.com\/ddos-attacks-mitigation-strategies\/\" target=\"_blank\" rel=\"noreferrer noopener\">DDoS<\/a> incidents, this botnet leveraged compromised router firmware to amass approximately 300,000 active devices worldwide.<\/p>\n<p>Researchers first detected unusual spikes of <a href=\"https:\/\/cybersecuritynews.com\/attaxion-releases-agentless-traffic-monitoring-for-immediate-risk-prioritization\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious traffic<\/a> targeting major infrastructure providers, prompting deeper investigation into the underlying threat.<\/p>\n<p>XLab analysts noted striking similarities between AISURU\u2019s attack methodology and earlier campaigns, yet the scale and sophistication of this operation far surpassed previous benchmarks.<\/p>\n<p>Propagation of AISURU began in April 2025 when threat actors exploited a vulnerability in Totolink router firmware update servers.<\/p>\n<p>By altering the firmware URL to point to a malicious script, every device performing an automatic update became infected.<\/p>\n<p>In a matter of weeks, the size of AISURU\u2019s network swelled to over 100,000 routers, and by September 2025, the botnet had consolidated around 300,000 nodes.<\/p>\n<p>XLab researchers <a href=\"https:\/\/blog.xlab.qianxin.com\/super-large-scale-botnet-aisuru-en\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the use of GRE tunneling to distribute traffic loads across multiple command-and-control (C2) servers, enabling the botnet to orchestrate a simultaneous flood of packets that overwhelmed target networks with ease.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiswkUL3vn1-u91jX9bIP_tISZciJ213hemnEJhtjn9eEPQfjRU4jutUQXB6vS_wnQLC4-UbBkEbB0zwfUE_BPUWa_DtCfsB8su7EnoxYeWCbq64gYpSilYlNv-GVeqrMaWJBweD5PVrwvnGkvjMRe9UFi6n27747-_-thUIkM5gPD-o7JEw2yWWBKlqvM\/s16000\/Cloudflare%2520Mitigates%252011.5%2520Tbps%2520DDoS%2520Attack%2520%28Source%2520-%2520XLab%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Cloudflare Mitigates 11.5 Tbps DDoS Attack (Source \u2013 XLab)<\/figcaption><\/figure>\n<\/div>\n<p>The impact of the 11.5 Tbps attack was felt globally as service providers scrambled to mitigate the flood of SYN, UDP, and DNS amplification requests.<\/p>\n<p>Affected organizations reported intermittent outages and service degradation, highlighting the potency of combining large-scale IoT compromise with advanced evasion techniques.<\/p>\n<p>XLab analysts identified the rapid shift from traditional amplification vectors to custom-crafted packet sequences designed to bypass legacy mitigation tools, an innovation that allowed AISURU to set new world records in DDoS throughput.<\/p>\n<p>While AISURU\u2019s distributed architecture and bandwidth capacity are staggering on their own, the malware\u2019s underlying behavior reveals a deeper level of technical refinement.<\/p>\n<p>Its dual-version propagation engine demonstrates continuous evolution, integrating both zero-day exploits and known N-day vulnerabilities to expand its reach.<\/p>\n<p>Equally concerning is its modular design, which facilitates swift updates to encryption, communication protocols, and attack commands without requiring a complete overhaul of the malware codebase.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-firmware-update-hijacking\"><strong>Infection Mechanism: Firmware Update Hijacking<\/strong><\/h2>\n<p>Delving into AISURU\u2019s infection mechanism uncovers a deceptively simple yet devastating approach.<\/p>\n<p>In April 2025, attackers breached Totolink\u2019s firmware update server, planting a shell script named <code>t.sh<\/code> that redirected devices to download the AISURU payload.<\/p>\n<p>Once executed, the script set up persistent execution by modifying <code>\/etc\/rc.local<\/code> entries and disabling the Linux OOM Killer via <code>\/proc\/self\/oom_score_adj<\/code>, ensuring the bot remained resident across reboots.<\/p>\n<p>The payload binary, renamed to <code>libcow.so<\/code>, avoided detection by masquerading as a common system daemon such as <code>telnetd<\/code> or <code>dhclient<\/code>.<\/p>\n<p>Upon initialization, AISURU performs environment checks to terminate itself under virtualized or analysis environments by scanning for virtualization artifacts and debugging tools.<\/p>\n<p>It then establishes a secure channel with C2 servers via a custom AES-XOR hybrid protocol, exchanging commands that range from DDoS instructions to residential proxy assignments.<\/p>\n<p>One illustrative snippet of the <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> routine follows:-<\/p>\n<pre class=\"wp-block-code\"><code># Persistence setup in \/etc\/rc.local\necho \"\/usr\/lib\/libcow.so &amp;\" &gt;&gt; \/etc\/rc.local\nchmod +x \/usr\/lib\/libcow.so<\/code><\/pre>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiGbEb3aZtEWR_W0Us0-2fFvBgDMWo-OsS8YUwQZ6ecty7aGebf7t5F6VOekf_iNLP2c1DdutihIjK51FKTdNzaG21IMPYosOxqopuajmjUZ4CylESkZUktY9lYdeDp7mwax9gHRhcPfBrhVqg7duGzHL2kJRQQg4hmtlXSq3L8W4jQtnv4jbgCCdV0TfM\/s16000\/Malicious%2520script%2520%28Source%2520-%2520Xlab%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Malicious script (Source \u2013 XLab)<\/figcaption><\/figure>\n<\/div>\n<p>This mechanism underscores the threat actors\u2019 mastery over both traditional Linux administration and bespoke malware <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">engineering<\/a>, enabling AISURU to maintain dominance in the DDoS ecosystem.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Free live\u00a0webinar\u00a0on new malware tactics from our analysts! Learn advanced detection techniques -&gt;\u00a0<a href=\"https:\/\/anyrun.webinargeek.com\/new-malware-tactics-cases-detection-tips-for-socs?cst=li_csn\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Register for Free<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/aisuru-botnet-with-300000-hijacked-routers\/\">AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/aisuru-botnet-with-300000-hijacked-routers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack Since early 2025, the cybersecurity community has witnessed an unprecedented surge in distributed denial-of-service (DDoS) bandwidth, culminating in a record-shattering 11.5 Tbps assault attributed to a botnet named AISURU. Emerging from XLab\u2019s continuous monitoring of global DDoS incidents, this botnet leveraged [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6948","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6948"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6948"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6948\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6948"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6948"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6948"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}