US and friends disrupt world's largest DDoS botnet responsible for record 31.4 Tbps global attacks

DDoS attack
(Image credit: FrameStockFootages / Shutterstock)

  • An international operating has disrupted four global botnets
  • The botnets operated over 3 million devices for DDoS attacks
  • The US, Canada, and Germany worked together to disrupt infrastructure and individuals

A global botnet responsible for a record breaking 31.4 Tbps DDoS attack has been disrupted by an international operation.

Law enforcement from the United States, Germany, and Canada targeted Command and Control (C2) infrastructure, virtual servers, and internet domains used to infect Internet of Things (IoT) devices.

The US Justice Department said the infrastructure was being used by Aisuru, KimWolf, JackSkid, and Mossad, and contained more than three million infected devices across the globe.

Article continues below

Global botnet disruption

The Justice Department explained that the operation was conducted simultaneously, with partners in Canada and Germany targeting the individuals responsible for operating the botnets.

“Some of these attacks measured approximately 30 Terabits per second, which were record-breaking attacks,” the Justice Department added.

The Aisuru botnet has been used in numerous record breaking DDoS attacks, including a 15.72 Tbps attack against Microsoft Azure. The KimWolf botnet operated over 1.8 million Android devices, while the Justice Department said the lesser-known JackSkid group has “launched more than 90,000 DDoS attack commands.” The Mossad botnet launched over 1,000 attack commands

DDoS botnets usually consist of internet connected ‘smart’ devices such as digital video recorders, web cameras, or Wi-Fi routers - but almost any internet connected device can be used as part of a botnet.

The companies responsible for creating these internet connected devices often do not roll out regular software updates, leaving the devices at risk of being hijacked. For example, the KimWolf botnet was largely made up of smart TV and media devices.

“Today, the United States joined international law enforcement partners in coordinated enforcement actions to disrupt DDoS threats impacting Alaskans and victims around the world,” said U.S. Attorney Michael J. Heyman for the District of Alaska.

“Effective collaboration bolsters our collective ability to combat emerging threats. The United States is steadfast in our commitment to safeguarding critical internet infrastructure and fighting the cybercriminals who jeopardize its security, wherever they might live.”


Best antivirus software header
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Benedict Collins
Senior Writer, Security

Benedict has been with TechRadar Pro for over two years, and has specialized in writing about cybersecurity, threat intelligence, and B2B security solutions. His coverage explores the critical areas of national security, including state-sponsored threat actors, APT groups, critical infrastructure, and social engineering.

Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the Centre for Security and Intelligence Studies at the University of Buckingham, providing him with a strong academic foundation for his reporting on geopolitics, threat intelligence, and cyber-warfare.

Prior to his postgraduate studies, Benedict earned a BA in Politics with Journalism, providing him with the skills to translate complex political and security issues into comprehensible copy.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.