Law enforcement agencies from the United States, Canada, and Germany have successfully dismantled four separate botnets that had compromised more than three million Internet of Things devices including routers and surveillance cameras. The four botnets—Aisuru, Kimwolf, JackSkid, and Mossad—have been linked to numerous large-scale distributed denial-of-service attacks capable of rendering virtually any target inaccessible.

The U.S. Justice Department's action involved the Department of Defense Office of Inspector General's Defense Criminal Investigative Service executing seizure warrants against multiple U.S.-based domains, virtual servers, and related infrastructure used in DDoS operations targeting Department of Defense internet addresses.

Authorities allege that unidentified individuals operating these botnets launched hundreds of thousands of DDoS attacks, frequently extorting money from victims. Targeted organizations reported losses and remediation costs reaching tens of thousands of dollars in some cases.

The scale of attacks varied significantly across the four botnets. Aisuru initiated over 200,000 attack commands, while JackSkid was responsible for at least 90,000 attacks. Kimwolf generated more than 25,000 attack commands, and Mossad carried out approximately 1,000 digital assaults.

The enforcement action aimed to prevent additional infections of victim devices and substantially reduce or eliminate the botnets' capacity to execute future attacks. The DCIS led the investigation with assistance from the FBI's Anchorage Field Office and support from nearly two dozen technology firms.

By working closely with DCIS and our international law enforcement partners, we collectively identified and disrupted criminal infrastructure used to carry out large-scale DDoS attacks

Special Agent in Charge Rebecca Day of the FBI Anchorage Field Office

Timeline and Technical Evolution

Aisuru first appeared in late 2024 and by mid-2025 was executing record-setting DDoS attacks while rapidly spreading to additional IoT devices. In October 2025, operators used Aisuru to launch Kimwolf, a derivative variant featuring an innovative propagation technique that enabled infection of devices protected by users' internal network firewalls.

The security company Synthient publicly revealed the vulnerability exploited by Kimwolf on January 2, 2026. While this disclosure slowed Kimwolf's expansion, subsequent IoT botnets have since emerged adopting similar spreading tactics and competing for access to the same vulnerable device population. The DOJ noted that JackSkid similarly targeted systems within internal networks comparable to Kimwolf's methodology.

International Enforcement and Suspects

The U.S. disruption operation coincided with law enforcement actions in Canada and Germany targeting individuals suspected of operating the four botnets, though specific details regarding the suspected operators were not disclosed by the DOJ.

In late February, KrebsOnSecurity identified a 22-year-old Canadian individual as a primary operator of the Kimwolf botnet. Sources with knowledge of the investigation indicated that another leading suspect is a 15-year-old resident of Germany.

Source: Krebs on Security