Tec Nikan
فارسی
Talk to us
All news

US Authorities Disrupt Four IoT Botnets Spanning Three Million Devices

The Aisuru, Kimwolf, JackSkid and Mossad botnets were disrupted in March 2026 after infecting more than three million routers, cameras, recorders and smart TVs.

IoT securitybotnetDDoSAisuruenforcement

In March 2026 the US Department of Justice disrupted four IoT botnets — Aisuru, Kimwolf, JackSkid and Mossad — which together had infected more than three million devices worldwide, including home routers, web cameras, digital video recorders and smart TVs.

The Aisuru network was behind one of the largest DDoS attacks recorded, peaking at 29.7 Tbps. The devices behind that figure were overwhelmingly consumer-grade equipment running outdated firmware with unchanged default credentials.

That detail is the part with a lesson in it. An attack of that scale was not assembled through novel exploitation; it was assembled by logging into devices with passwords that were never changed. Takedowns remove infrastructure but not the underlying population, and the same devices remain online and reachable afterwards. Anyone operating a fleet can act on this directly: unique per-device credentials, no administrative service exposed by default, and a firmware update path that actually gets used.

Source: Asimily

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.