# International Coordinated Takedown Dismantles Four Major IoT Botnets Behind Record DDoS Attacks


A coordinated law enforcement operation involving the United States, Canada, and Germany has successfully disrupted four sophisticated IoT botnets responsible for some of the internet's most destructive distributed denial-of-service campaigns. The action marks a significant victory against criminal infrastructure that compromised more than three million internet-connected devices and generated hundreds of thousands of DDoS attacks targeting organizations worldwide.


## The Scope of the Threat


The four botnets—Aisuru, Kimwolf, JackSkid, and Mossad—collectively represent one of the most damaging DDoS infrastructures discovered in recent years. Law enforcement agencies documented a staggering volume of attack activity originating from these networks:


| Botnet | Attack Commands Issued |

|--------|------------------------|

| Aisuru | 200,000+ |

| JackSkid | 90,000+ |

| Kimwolf | 25,000+ |

| Mossad | ~1,000 |


The botnets targeted critical infrastructure, government systems, and private sector organizations, with some victims reporting remediation costs exceeding tens of thousands of dollars. Operators behind these networks reportedly used the botnets to conduct extortion campaigns, leveraging the threat of devastating DDoS attacks to demand payment from targets.


## Background and Context


The botnet ecosystem evolved dramatically over the period preceding the takedown. Aisuru, the oldest of the four, first emerged in late 2024 and rapidly escalated its capabilities. Within months, the botnet was conducting what security researchers characterized as record-breaking DDoS attacks while simultaneously infecting new vulnerable IoT devices at an alarming rate.


The situation intensified in October 2025 when operators deployed Kimwolf, a derivative of Aisuru that introduced a critical innovation in botnet propagation. Rather than limiting infections to devices directly exposed to the internet, Kimwolf incorporated a novel spreading mechanism capable of compromising devices hidden behind network firewalls and NAT (Network Address Translation) protections on home and office internal networks. This advancement significantly expanded the potential victim pool and made detection more challenging for network administrators.


The security community's visibility into Kimwolf's operations increased dramatically on January 2, 2026, when the security firm Synthient publicly disclosed the specific vulnerability that Kimwolf exploited for rapid propagation. The disclosure temporarily slowed Kimwolf's growth trajectory, but the damage had been done—the methodology quickly became a template for successor botnets.


## Technical Details and Spread Mechanisms


What made these botnets particularly effective was their ability to penetrate network perimeters traditionally considered secure. JackSkid operated with similar internal network targeting capabilities as Kimwolf, suggesting a shared understanding among operators about optimal propagation strategies.


The vulnerabilities leveraged by these botnets primarily affected IoT devices—routers, web cameras, network-attached storage devices, and other consumer and enterprise equipment that often ship with weak default credentials or unpatched firmware. These devices represent a persistent security challenge: they frequently remain operational for years without security updates, operate with minimal visibility from users, and often lack advanced threat detection capabilities.


The speed of infection demonstrated by Aisuru's transition to Kimwolf illustrated how quickly botnet source code and techniques spread through criminal networks. Once a successful propagation method is established and publicly disclosed, competing criminal operators rapidly adopt and iterate on the technique.


## Law Enforcement Coordination and Disruption


The Department of Justice, working through the Department of Defense Office of Inspector General's Defense Criminal Investigative Service, executed seizure warrants targeting U.S.-registered infrastructure supporting the botnets. The action included removal of command-and-control servers, domain registrations, and virtual hosting infrastructure that operators used to direct infected devices.


"By working closely with DCIS and our international law enforcement partners, we collectively identified and disrupted criminal infrastructure used to carry out large-scale DDoS attacks," stated Rebecca Day, Special Agent in Charge of the FBI's Anchorage Field Office, highlighting the distributed nature of the investigation.


Approximately two dozen technology companies assisted in the operation, providing forensic data, network intelligence, and technical expertise that proved essential to identifying the infrastructure and understanding the botnets' operational patterns.


## Identifying the Operators


The disruption coincided with law enforcement actions in Canada and Germany targeting individuals allegedly operating the botnets. Subsequent reporting by security journalists identified a 22-year-old Canadian man as a core operator of the Kimwolf botnet. Intelligence sources further indicated that a 15-year-old resident of Germany served as another primary suspect in the operation—a revelation underscoring the sometimes-youthful demographics of sophisticated cybercriminal operators.


## Implications and Ongoing Threats


While the takedown represents a meaningful blow to active DDoS-for-hire operations, the underlying vulnerability remains unresolved. The public disclosure of Kimwolf's spreading technique has already inspired successor botnets employing similar methodologies to target the same vulnerable IoT devices. The months following the January 2026 vulnerability announcement saw proliferation of copycat variants, each competing for infection of the limited but substantial pool of vulnerable IoT devices worldwide.


The incident underscores a persistent challenge in cybersecurity: the difficulty of permanently disrupting criminal infrastructure when the underlying technical vulnerabilities remain unpatched across millions of devices. Device manufacturers have inconsistent security update practices, many device owners never apply available patches, and older hardware frequently never receives security improvements from vendors.


## Recommendations


Organizations and individuals can reduce exposure to IoT botnet recruitment through several concrete measures:


  • Maintain firmware updates on all internet-connected devices, prioritizing security patches
  • Change default credentials on network devices, routers, and cameras immediately upon deployment
  • Implement network segmentation to isolate IoT devices from critical systems
  • Monitor egress traffic from internal networks for signs of DDoS attack activity
  • Deploy rate limiting on external-facing services to mitigate DDoS impact even if infection occurs

  • ## HackWire Analysis


    The coordinated takedown demonstrates that international law enforcement has improved its capacity to target distributed botnet infrastructure, yet the operation's limited long-term impact illustrates the fundamental asymmetry: it is far easier for criminals to identify and exploit new vulnerabilities in millions of IoT devices than for manufacturers and users to apply patches. The appearance of successor botnets within weeks confirms that disrupting infrastructure addresses symptoms rather than causes. Meaningful progress requires either systematic improvement in IoT security hygiene across manufacturing and deployment, or significantly increased financial consequences for operators—potentially the more realistic path given economic incentives. The extreme youth of some suspected operators also raises questions about recruitment and radicalization within cybercriminal communities, suggesting the issue extends beyond mere technical mitigation.