Security Stop-Press: Aisuru Botnet Drives Terabit-Scale DDoS Attacks

The Aisuru botnet, built from millions of hijacked routers and other cheap IoT devices, has driven DDoS attacks to levels the internet has never seen before.

Cloudflare, the internet security provider, reports that Aisuru now controls up to four million infected devices, mainly spread across Asia. Indonesia is the biggest source of its traffic. These devices have launched repeated multi terabit attacks, including a Q3 peak of 29.7 Tbps that blasted traffic across thousands of ports at once.

Activity has risen sharply. Cloudflare says it stopped 1,304 major Aisuru attacks in Q3 and 2,867 so far this year, as network layer attacks jumped 87 percent quarter on quarter while HTTP attacks fell.

Some sectors have faced far heavier targeting. For example, generative AI firms saw a 347 percent spike in September, and industries linked to rare earths and EV trade tensions also recorded sharp increases.

Aisuru’s reach is made worse by the fact that parts of the botnet can be hired cheaply, enabling short, intense attacks that often end before older defences can respond.

Businesses can reduce their risk by using always on network protection, automating detection, and keeping exposed systems patched, since traditional on demand tools cannot keep pace with attacks of this speed and scale.

Security Stop-Press: AI Tools Fuel Record Rise in DDoS Botnets

Attackers are using artificial intelligence (AI) to build record-breaking DDoS botnets, according to new data from internet security firm Qrator Labs.

The company reports that one botnet it tracked contained 5.76 million infected devices, a 25-fold increase on last year’s largest network. Qrator’s CTO, Andrey Leskin, said AI now lets attackers “find and capture devices much faster and more efficiently,” driving unprecedented growth.

Brazil has overtaken Russia and the US as the biggest source of application-layer DDoS attacks, accounting for 19 per cent of malicious traffic, while Vietnam’s share has surged as unsecured devices multiply across developing regions. Fintech and e-commerce remain the top targets, with peak attacks reaching 1.15 Tbps.

Experts warn that AI tools are lowering the barriers to entry for cybercriminals, enabling large-scale automated attacks. Businesses are urged to use layered DDoS protection, keep connected devices updated, and monitor for unusual network activity to defend against this new AI-driven threat.

Security Stop-Press: Record-breaking DDoS Attack Highlights Growing Cybersecurity Threats

Cloudflare’s latest DDoS Threat Report for Q4 2024 highlights a dramatic surge in Distributed Denial of Service (DDoS) attacks, including a record-breaking 5.6 Tbps assault.

The web security and infrastructure company’s report reveals a 53 per cent year-over-year rise in DDoS activity, with Cloudflare blocking 21.3 million attacks in 2024, 6.9 million of which occurred in Q4, a staggering 83 per cent increase from the same period in 2023!

The largest attack, a 5.6 Tbps assault by a Mirai-variant botnet of over 13,000 IoT devices, targeted an ISP in Eastern Asia. Cloudflare says it mitigated it autonomously within seconds, preventing any disruption. Hyper-volumetric attacks exceeding 1 Tbps grew by 1,885 per cent quarter-over-quarter, reflecting the increasing scale and intensity of these threats. Nearly half of all attacks targeted OSI Layers 3 and 4, with the remainder focused on HTTP-based attacks, predominantly launched by botnets exploiting IoT devices.

Cloudflare’s report also highlighted how emerging attack methods like Memcached and BitTorrent DDoS vectors have seen dramatic growth, and ransom-motivated attacks surged by 78 per cent compared to Q3. The report also identifies telecommunications and marketing as the most attacked industries, with China, the Philippines, and Taiwan being key hotspots. Cloudflare says those responsible for the attacks include competitors, state-sponsored groups, and disgruntled users, highlighting diverse motives behind these incidents.

To counter these growing threats, businesses should deploy always-on, automated DDoS protection, secure all connected devices, and adopt proactive defence strategies. With attacks becoming faster and more sophisticated, real-time mitigation and robust security are critical to minimising risk.

Security Stop Press : DDoS Doubled!

A Threat Landscape report from cyber security company Imperva has revealed that the number of Distributed Denial of Service (DDoS) attacks more than doubled globally last year, with the upward trend continuing in the first half of this year.

DDoS attacks overwhelm a target system with excessive traffic from multiple sources (multiple compromised systems, often infected with malware), causing it to slow down or crash, thereby denying service to legitimate users.

Imperva’s report attributes the increase in this type of attack to factors like geopolitical tensions, e.g. attacks on Ukraine are up by 519 per cent and attacks on Israel are up by 118 per cent. The report identifies the most attacked industries as being financial services, telecoms, and ISPs, which collectively account for around 60 per cent of all Layer 7 (flooding a website with fake traffic) DDoS attacks.

The advice to businesses looking to protect themselves from DDoS attacks is to implement robust security measures, such as using DDoS protection services, monitoring traffic, and having an incident response plan.