Arelion says Aisuru drives one third of DDoS traffic
Fri, 24th Jul 2026 (Today)
Arelion has published a report saying the Aisuru botnet accounted for about one third of DDoS attack traffic on its network, based on traffic data from its global backbone.
The report describes a rise in very large distributed denial-of-service attacks, with the biggest incident observed on Arelion's network reaching 6.1 terabits per second. It says average attack volume increased sharply while average attack duration fell, pointing to shorter, more frequent attack campaigns.
Arelion identified Aisuru as the most disruptive botnet in its dataset, linking it to major attacks against gaming and cloud providers. According to the report, the botnet drew on more than 500,000 compromised internet of things devices and Android-based systems, and attacks linked to it often exceeded 1 Tbps across the company's backbone.
By early 2026, a variant known as KimWolf had infected more than 2 million Android TV and streaming devices, according to the report. That shift illustrates how the threat surface has moved from traditional data centre systems to consumer devices on home networks, which can generate large volumes of malicious traffic from widely distributed endpoints.
Attack patterns
Attack behaviour has also changed. Earlier campaigns often relied on smaller, faster packets designed to avoid detection, but Aisuru combined large traffic volumes with multi-vector methods, adding pressure on mitigation systems built for less intense attacks.
In Arelion's figures, average attack traffic measured in gigabits per second rose 22 per cent to 6,120 Gbps. Million packets per second increased 60 per cent to 999 Mpps, while peak attack traffic in Gbps jumped 290 per cent.
At the same time, average attack duration dropped 20 per cent to 8.9 minutes. The report said that pattern was consistent with "carpet bombing" campaigns, in which attackers spread short bursts of traffic across a broader set of targets.
The findings also point to the role of artificial intelligence in changing how such attacks are launched. Arelion said AI has lowered the barrier to entry for complex DDoS operations by enabling automated botnets to mount multi-vector attacks more quickly and with less effort.
Geopolitical dimension
Beyond criminal botnets, nation-state actors remained active in the DDoS landscape, the report said. It highlighted continued politically motivated attacks across NATO-aligned European countries including Spain and Bulgaria, and described the Middle East as a key front for campaigns targeting critical infrastructure.
Arelion said some state-aligned groups had intensified DDoS attacks alongside wider geopolitical conflict. The report added that restrictions on domestic internet access in some countries had coincided with support for cyberattacks abroad, making DDoS a tool that could support military objectives both indirectly and directly.
The broader trend reflects changes in internet infrastructure as well as attacker methods. The spread of internet-connected consumer devices, distributed cloud systems and 5G networks has given botnets access to more endpoints and more bandwidth, allowing them to scale attacks more easily than in previous years.
Network response
Arelion said its backbone absorbed hundreds of daily attacks attributed to Aisuru with limited disruption to customers. The company cited one unnamed online gaming platform that faced multi-vector attacks peaking at several terabits per second, where traffic filtering at the network layer allowed legitimate sessions to continue.
That example reflects a wider industry shift towards mitigation methods deployed within carrier networks rather than only at customer premises or in data centres. As attacks grow larger and more dispersed, telecoms operators and service providers are under pressure to handle malicious traffic earlier in the path before it reaches end users.
Mattias Fridström, Vice President and Chief Evangelist at Arelion, said the data showed a substantial change in the threat environment.
"AI has shifted the DDoS threat landscape significantly, making it much easier for cybercriminals to launch massive, automated multi-vector attacks with capacities far exceeding anything we've seen before," Fridström said. "Attacks are happening at scale, so service providers and enterprises must defend at scale. As attack traffic becomes larger, more distributed and less predictable, organizations require both the capacity and agility to adapt to unexpected traffic patterns. These findings highlight the need for always-on, network-level protection that can absorb massive terabit-scale floods and for coordinated, large-scale mitigation efforts across the Internet's entire ecosystem."