s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932741 high

📛 Threat Title

Aisuru: Domain that is used for botnet Command&control (C&C) kirk.velyra.ru

Category: Aisuru Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Aisuru. Confidence: 100. First seen: 2026-09-25 09:05:31 UTC. Reporter: deepfield. Tags: airashi, AISURU, botnet, DDoS, Mirai.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain kirk.velyra.ru UrlVoid 2 / 36

IOC database

Type
domain
Value
kirk.velyra.ru
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Aisuru. Confidence: 100. First seen: 2026-09-25 09:05:31 UTC. Reporter: deepfield. Tags: airashi, AISURU, botnet, DDoS, Mirai.

Remediations (10)

  • web:cybersecuritynews.com

    In a matter of weeks, the size of AISURU's network swelled to over 100,000 routers, and by September 2025, the botnet had consolidated around 300,000 nodes. XLab researchers identified the use of GRE tunneling to distribute traffic loads across multiple command-and-control (C2) servers, enabling the botnet to orchestrate a simultaneous flood ...

  • web:gist.github.com

    Confirmed: 11.5 Tbps attack early September 2025 (Cloudflare), definitively attributed to Aisuru botnet by XLab researchers Aisuru : ~300,000-node IoT botnet , capable of sustained multi-terabit attacks, operated by three-person group Key Findings: Attack durations: 35-65 seconds (too short for manual mitigation )

  • web:github.com

    This report documents the Command & Control (C2) infrastructure of the AISURU botnet , a large-scale DDoS botnet responsible for record-breaking attacks including an 11.5 Tbps attack in September 2025. The botnet compromised approximately 300,000 devices, primarily Totolink routers, through a firmware update server breach in April 2025.

  • web:krebsonsecurity.com

    Over this past week, Cloudflare started redacting portions of the malicious Aisuru domains from its Top Domains list, leaving only their domain suffix visible.

  • web:www.bitsight.com

    Aisuru operates as a high volumetric botnet with its traffic being predominantly UDP-based (55%), targeting diverse sectors including technology, finance, and government. More recently, the botnet pivoted to targeting exposed Android Debug Bridge (ADB) instances, enabling local network scanning and the deployment of proxyware on vulnerable devices.

  • web:www.bsi.bund.de

    Aisuru is a large-scale IoT botnet first identified in August 2024. The malware infects poorly secured internet-connected devices such as home routers, surveillance cameras and other IoT devices and incorporates them into a remotely controlled network.

  • web:www.netscout.com

    Attack traffic generated by TurboMirai DDoS botnets such as Aisuru is not spoofed because the botnet code does not run in a privileged context on compromised devices; additionally, most botnet nodes are sited on broadband access networks that have source-address validation (SAV) mechanisms enabled by default at the access layer.

  • web:www.protoslabs.io

    Critical threat intelligence on the Aisuru botnet , responsible for record 29.7 Tbps DDoS attacks. Review TTPs, IOCs, and essential mitigation steps now.

  • web:www.radware.com

    The Aisuru botnet is a massive, Mirai-derived network of malware-infected Internet of Things (IoT) devices, routers, cameras, and cloud VMs that has been used to launch some of the largest hyper-volumetric distributed denial-of-service (DDoS) attacks in history.

  • web:www.secpod.com

    Its architecture incorporates custom encryption, multi-layered command-and-control obfuscation, process masquerading, and anti-analysis features designed to ensure persistence and resilience. AISURU operators exploit a broad range of vulnerabilities across various vendors, allowing the botnet to propagate globally at high speed.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.