Loading cryptocurrency prices...

Microsoft Thwarts Record 15.72 Tbps IoT Botnet DDoS Attack

Microsoft Neutralizes Record 15.72 Tbps DDoS Attack in Australia Launched by AISURU IoT Botnet

  • Microsoft detected and stopped a record-breaking 15.72 terabits per second (Tbps) DDoS attack in Australia.
  • The assault was launched by the AISURU IoT botnet, comprised of over 500,000 infected devices.
  • AISURU primarily targets online gaming and avoids government and military systems.
  • Botnets like AISURU also conduct activities such as credential stuffing, AI-driven web scraping, spamming, and phishing.
  • Another IoT botnet, Eleven11, was recently dismantled after launching thousands of DDoS attacks.

On Monday, Microsoft announced it had automatically detected and mitigated a massive distributed denial-of-service (DDoS) attack aimed at a single endpoint in Australia. The attack reached 15.72 Tbps and nearly 3.64 billion packets per second (pps), marking it as the largest cloud-based DDoS assault ever recorded. The targeted party remains unidentified.

- Advertisement -

The attack originated from an extensive Internet of Things (IoT) botnet known as AISURU, classified as TurboMirai-type, involving over 500,000 source IPs distributed globally. Microsoft’s Sean Whalen stated the attack consisted of high-rate UDP floods with minimal source spoofing and randomized source ports, aiding in tracing and blocking the traffic (source).

Data provided by QiAnXin XLab indicates that AISURU controls about 300,000 infected devices, mainly routers, security cameras, and DVRs. This botnet has been responsible for some of the largest DDoS attacks recorded so far. According to a recent NETSCOUT report, AISURU operates with a limited clientele and reportedly avoids targeting government, law enforcement, military, and national security infrastructures. Most attacks appear focused on online gaming environments (source).

Besides DDoS attacks exceeding 20 Tbps, AISURU also facilitates various illicit activities like credential stuffing, AI-driven web scraping, spamming, phishing, and offers a residential proxy service. Microsoft noted the increasing attack scale is linked to faster broadband speeds and more powerful IoT devices.

Separately, NETSCOUT detailed another TurboMirai botnet named Eleven11 (also known as RapperBot), which carried out approximately 3,600 DDoS attacks through hijacked IoT devices between February and August 2025. Authorities recently arrested operators and dismantled this botnet. Some of its command-and-control servers used the “.libre” top-level domain, part of the OpenNIC system, which bypasses traditional Internet DNS managed by ICANN. Despite its takedown, compromised devices remain at risk of being recruited for future botnets (source).

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Critical WordPress Flaw CVE-2025-6389 Exploited in Wild Attack

A remote code execution vulnerability (CVE-2025-6389) in the Sneeit Framework WordPress plugin is being...

ChatGPT Picks Solana and Avalanche to 10x in 2026 Crypto Surge

The cryptocurrency market has shown bullish trends with Bitcoin reaching a high of $126,080...

Binance Secures Three Licenses to Operate in Abu Dhabi’s ADGM

Binance received three licenses from Abu Dhabi’s Financial Services Regulatory Authority (FSRA) for exchange,...

Iran’s MuddyWater Hacks with UDPGangster Malware via Phishing

An Iranian Hacking group called MuddyWater is using a new backdoor Malware named UDPGangster...

XRP Faces Heavy Short Selling, Price Drop Risks Looming

XRP faces significantly higher short-selling positions compared to long positions among traders.Short positions on...
- Advertisement -

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...