By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
Computing

DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

News Room
Last updated: 2026/03/20 at 2:38 AM
News Room Published 20 March 2026
Share
DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
SHARE

Ravie LakshmananMar 20, 2026Botnet / Network Security

The U.S. Department of Justice (DoJ) on Thursday announced the disruption of command-and-control (C2) infrastructure used by several Internet of Things (IoT) botnets like AISURU, Kimwolf, JackSkid, and Mossad as part of a court-authorized law enforcement operation.

The effort also saw authorities from Canada and Germany targeting the operators behind these botnets, with a number of private sector firms, including Akamai, Amazon Web Services, Cloudflare, DigitalOcean, Google, Lumen, Nokia, Okta, Oracle, PayPal, SpyCloud, Synthient, Team Cymru, Unit 221B, and QiAnXin XLab assisting in the investigation efforts.

“The four botnets launched distributed denial-of-service (DDoS) attacks targeting victims around the world,” the DoJ said. “Some of these attacks measured approximately 30 Terabits per second, which were record-breaking attacks.”

In a report last month, Cloudflare attributed AISURU/Kimwolf to a massive 31.4 Tbps DDoS attack that occurred in November 2025 and lasted only 35 seconds. Towards the end of last year, the botnet is also assessed to have engaged in hyper-volumetric DDoS attacks that had an average size of 3 billion packets per second (Bpps), 4 Tbps, and 54 million requests per second (Mrps).

Independent security journalist Brian Krebs also traced the administrator of Kimwolf to a 23-year-old Jacob Butler (aka Dort) from Ottawa, Canada. Butler told Krebs he has not used the Dort persona since 2021 and claimed someone is impersonating him after compromising his old account.

Butler also said, “he mostly stays home and helps his mom around the house because he struggles with autism and social interaction.” According to Krebs, the other prime suspect is a 15-year-old residing in Germany. No arrests have been announced.

The botnet has conscripted more than 2 million Android devices into its network, most of which are compromised, off-brand Android TVs. In all, the four botnets are estimated to have infected no less than 3 million devices worldwide, such as digital video recorders, web cameras, or Wi-Fi routers, of which hundreds of thousands are located in the U.S.

“The Kimwolf and JackSkid botnets are accused of targeting and infecting devices which are traditionally ‘firewalled’ from the rest of the internet. The infected devices were enslaved by the botnet operators,” the DoJ said. “The operators then used a ‘cybercrime as a service’ model to sell access to the infected devices to other cyber criminals.”

These infected devices were then used to conduct DDoS attacks against targets of interest across the world. Court documents allege that the four Mirai botnet variants have issued hundreds of thousands of DDoS attack commands –

  • AISURU – >200,000 DDoS attack commands
  • Kimwolf – >25,000 DDoS attack commands
  • JackSkid – >90,000 DDoS attack commands
  • Mossad – >1,000 DDoS attack commands

“Kimwolf represented a fundamental shift in how botnets operate and scale. Unlike traditional botnets that scan the open internet for vulnerable devices, Kimwolf exploited a novel attack vector: residential proxy networks,” Tom Scholl, VP/Distinguished Engineer at AWS, said in a post shared on LinkedIn.

“By infiltrating home networks through compromised devices—including streaming TV boxes and other IoT devices — the botnet gained access to local networks that are typically protected from external threats by home routers.”

Akamai said the hyper-volumetric botnets generated attacks exceeding 30 Tbps, 14 billion packets per second, and 300 Mrps, adding that cybercriminals leveraged these botnets to launch hundreds of thousands of attacks and demand extortion payments from victims in some cases.

“These attacks can cripple core internet infrastructure, cause significant service degradation for ISPs and their downstream customers, and even overwhelm high-capacity cloud-based mitigation services,” the web infrastructure company said.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Dolls, Not Tablets, Shine in Teaching Vital Skills to Children, Study Reveals Dolls, Not Tablets, Shine in Teaching Vital Skills to Children, Study Reveals
Next Article It’s your chance to grab a Google TV Streamer for just .99! It’s your chance to grab a Google TV Streamer for just $79.99!
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Telenor IoT expands global connectivity with launch of global APN | Computer Weekly
Telenor IoT expands global connectivity with launch of global APN | Computer Weekly
News
Scale Your Social Media Presence in 8 Ways: How Brands Keep Growing
Scale Your Social Media Presence in 8 Ways: How Brands Keep Growing
Computing
How To Tell If Your Replacement Car Key Is An OEM Or Third-Party – BGR
How To Tell If Your Replacement Car Key Is An OEM Or Third-Party – BGR
News
Playwright vs. Puppeteer: Head-to-head Comparison 2026 | HackerNoon
Playwright vs. Puppeteer: Head-to-head Comparison 2026 | HackerNoon
Computing

You Might also Like

Scale Your Social Media Presence in 8 Ways: How Brands Keep Growing
Computing

Scale Your Social Media Presence in 8 Ways: How Brands Keep Growing

7 Min Read
Playwright vs. Puppeteer: Head-to-head Comparison 2026 | HackerNoon
Computing

Playwright vs. Puppeteer: Head-to-head Comparison 2026 | HackerNoon

27 Min Read
The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks
Computing

The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks

8 Min Read
Ubuntu Maker Canonical Announces MicroCloud Cluster Manager
Computing

Ubuntu Maker Canonical Announces MicroCloud Cluster Manager

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?