s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.aisuru

📛 Threat Title

Malware family: Aisuru

Category: Aisuru First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.aisuru`. Printable name: Aisuru.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.aisuru VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.aisuru

IOC database

Type
domain
Value
elf.aisuru
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.aisuru

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.aisuru

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Aisuru .

  • web:blog.xlab.qianxin.com

    Overview Since 2025, peak bandwidth for global DDoS attacks has repeatedly broken historical records, rising from 3.12 Tbps at the start of the year to a staggering 11.5 Tbps recently. In multiple high-impact or record-breaking attack incidents, we consistently observed a botnet named AISURU operating behind the scenes.

  • web:cybersecuritynews.com

    AISURU botnet, exploiting Totolink routers, launched a record 11.5 Tbps DDoS using 300K devices, surpassing past attack benchmarks.

  • web:gist.github.com

    The widely-circulated 29.69 Tbps claim is UNCONFIRMED —appears only in social media, no mitigation vendor verification Confirmed: 22.2 Tbps attack on September 22, 2025 (Cloudflare), largest verified DDoS on record, suspected Aisuru involvement

  • web:krebsonsecurity.com

    Aisuru , the botnet responsible for a series of record-smashing distributed denial-of-service (DDoS) attacks this year, recently was overhauled to support a more low-key, lucrative and sustainable ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Aisuru DDoS Campaign: Threat Intelligence Assessment Aisuru 2025-09-23 ⋅ Bleeping Computer ⋅ Bill Toulas Cloudflare mitigates new record-breaking 22.2 Tbps DDoS attack Aisuru 2025-09-15 ⋅ Qianxin ⋅ Acey9, Alex.Turing, Wang Hao The Most Powerful Ever? Inside the 11.5Tbps-Scale Mega Botnet AISURU Aisuru 2025-05-20 ⋅ KrebsOnSecurity ⋅ ...

  • web:securityaffairs.com

    A new Mirai-based IoT botnet, dubbed Aisuru , was used to launch multiple high-impact DDoS attacks exceeding 20Tb/sec and/or 4gpps.

  • web:www.netscout.com

    Arbor Networks - DDoS Experts ASERT Threat Summary: Aisuru and Related TurboMirai Botnet DDoS Attack Mitigation and Suppression—October 2025—v1.0

  • web:www.protoslabs.io

    Critical threat intelligence on the Aisuru botnet, responsible for record 29.7 Tbps DDoS attacks. Review TTPs, IOCs, and essential mitigation steps now.

  • web:www.securityweek.com

    Malware & Threats TurboMirai-Class 'Aisuru' Botnet Blamed for 20+ Tbps DDoS Attacks A new class of Mirai-based DDoS botnets have been launching massive attacks, but their inability to spoof traffic enables device remediation .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.