7 min read

Why the IoT Botnet Takedown Is a Wake-Up Call for Enterprise Security

3 Million Infected Devices

On March 20, 2026, the US Department of Justice, alongside authorities in Germany and Canada, disrupted four of the largest DDoS botnets ever recorded. The networks, Aisuru, KimWolf, JackSkid, and Mossad, had collectively infected more than 3 million devices worldwide and were responsible for attacks that redefined what “large-scale” means in cybersecurity. The biggest single attack, a 31.4 Terabit-per-second UDP flood generated by the Aisuru botnet in November 2025, was nearly six times larger than the previous year’s record.

The devices that powered these attacks were not sophisticated corporate servers. They were DVRs, webcams, Wi-Fi routers, and off-brand Android TV set-top boxes, the kind of equipment sitting on home networks across the world, including the home networks of your remote workers.

What Actually Happened: The Operation

The joint law enforcement action targeted command-and-control (C2) infrastructure, virtual servers, and internet domains used to recruit and manage infected devices. Private sector firms, including Akamai, Amazon Web Services, Cloudflare, DigitalOcean, Google, Lumen, Nokia, Okta, Oracle, PayPal, and SpyCloud, assisted in the investigation.

According to the DOJ, the four botnets issued a combined total of more than 316,000 DDoS attack commands. Aisuru alone accounted for over 200,000. Some of those attacks targeted US Department of Defense systems. Others hit telecommunications providers. Victims were in some cases approached with extortion demands, pay, or the attacks continue.

German authorities identified two suspected administrators: one a 23-year-old in Ottawa, Canada, the other a 15-year-old in Germany. Searches were conducted at both residences. Cryptocurrency worth tens of thousands of dollars was seized. No formal arrests have been announced as of publication.

The Attack Scale That Should Recalibrate Your Risk Model

The numbers from this operation are not incremental, they represent a step-change in the threat landscape.

The 31.4 Tbps peak attack reached 200 million requests per second. Akamai reported attacks from these botnets exceeding 30 Tbps, 14 billion packets per second, and 300 million requests per second in separate incidents. Cloudflare’s threat research unit recorded 19 record-setting attacks in 2025 alone. The total number of DDoS attacks more than doubled in 2025 to 47.1 million, with network-layer attacks more than tripling year over year.

These are not the numbers of a niche threat. This is mainstream infrastructure risk.

The Home Network Vector That Changes Everything

The most important technical detail in this operation — the one that matters most to enterprise security teams, is how KimWolf recruited its devices.

Unlike traditional botnets that scan the open internet for unpatched systems, KimWolf exploited residential proxy networks. It infiltrated home networks through compromised devices, gaining access to local networks that are typically considered protected from external threats by home routers. It conscripted approximately 2 million devices, predominantly off-brand Android smart TVs and set-top boxes.

This is a critical distinction. KimWolf did not breach corporate perimeters directly. It compromised the home networks of ordinary people, and then used that foothold to expand further, launch attacks from trusted residential IP addresses, and in some cases establish pathways into networks that should have been unreachable.

For organisations with remote workforces, this is not an abstract concern. Every remote worker’s home network is a potential recruitment zone. The DVR in the living room, the smart TV in the home office, the webcam above the front door. none of these devices are managed by IT, monitored by security tools, or visible to enterprise security stacks. They share a network with the corporate laptop. And as KimWolf demonstrated, they can be conscripted without the user ever knowing.

Why Enterprise Security Tools Missed This

Traditional security architecture was not designed for this problem. Endpoint Detection and Response (EDR) tools protect managed corporate devices. Mobile Device Management (MDM) platforms cover enrolled endpoints. Firewalls and network monitoring tools watch corporate perimeters.

None of them see inside a remote worker’s home network. None of them know that a compromised Android TV sits on the same subnet as the managed laptop connecting to the corporate VPN. None of them can flag when a DVR that was fine on Monday is generating anomalous traffic by Wednesday because it has been silently recruited into a botnet.

This is the blind spot that the Aisuru and KimWolf operations exploited at scale. Research consistently shows that more than 70% of devices employees use in remote or hybrid work environments fall outside IT visibility. The botnet operators knew this. They targeted exactly those devices.

How Continuous Device Visibility Changes the Outcome

The scenario that KimWolf represents, compromised IoT devices on remote worker home networks being used as botnet nodes and residential proxy infrastructure, is precisely the problem that remote device intelligence is designed to address.

4Remote’s platform discovers every device on a remote worker’s network: managed, unmanaged, personal, and IoT. Not through agents installed on each device, but through agentless discovery that maps the full network environment in near real-time. A DVR. A smart TV. A webcam. An off-brand set-top box. All of it appears in the asset inventory, risk-scored and continuously monitored.

When a device behaves unexpectedly. new connections, unusual traffic patterns, changes in network posture, that signal is surfaced. In the KimWolf scenario, a device that has been silently recruited into a botnet does not stay invisible. It appears in the inventory. Its change in behaviour is detectable. The security team has the information they need to act before that device becomes a launchpad.

This is the difference between reactive and proactive. The global operation that disrupted Aisuru and KimWolf was a law enforcement success, but it came after 3 million devices were compromised, after 31.4 Tbps attacks hit their targets, after DoD systems were disrupted. The goal for enterprise security teams is not to wait for law enforcement to clean up the ecosystem. It is to ensure that the devices on your extended network perimeter never become part of the problem in the first place.

4Remote’s Professional, Enterprise, and Network editions are built for exactly this: continuous, agentless visibility across distributed environments, including the home networks where your workforce actually operates.

The Disruption Is Not the End

One final fact worth noting. On March 18th, two days before the takedown was announced. Nokia Deepfield researchers reported the active deployment of a new Mirai-derived botnet, targeting Android-based TV set-top boxes. The same device category. The same attack vector. A new operator.

History is clear on this point: botnet takedowns are operationally significant, but the underlying ecosystem, he pool of unmonitored, unpatched IoT devices on home and remote networks, does not go away. As long as those devices remain invisible to the organisations whose people use them, they will continue to be recruited.

The disruption of Aisuru and KimWolf is a success. It is also a reminder that the conditions that made them possible have not changed.

Key Takeaways

– The Aisuru, KimWolf, JackSkid, and Mossad botnets infected 3 million+ devices, primarily DVRs, webcams, Wi-Fi routers, and Android TV devices, and drove DDoS attacks peaking at 31.4 Tbps, nearly six times the 2024 record.

– KimWolf specifically targeted home networks via residential proxy networks, using compromised IoT devices as both attack infrastructure and network infiltration footholds.

– Enterprise security tools have no visibility into these devices, they are not managed endpoints, and they sit on the same home networks as corporate laptops used by remote workers.

Continuous, agentless device discovery is the proactive countermeasure, knowing every device on a remote worker’s network, and monitoring for vulnerabilities, is what prevents silent recruitment into a botnet.

– Takedowns are temporary; the device visibility gap is structural, a new botnet was already being deployed before this operation concluded. The underlying risk remains until the blind spot is closed.

See Every Device on Your Remote Workers’ Networks

The devices that powered the world’s largest DDoS botnet were hiding in plain sight, on home networks, completely invisible to the organisations whose employees used them. That gap is closable.

4Remote’s Professional, Enterprise, and Network editions give security teams continuous, agentless visibility into every device on remote worker networks, including the DVRs, smart TVs, and IoT devices that traditional tools have never been able to see.

*Sources
The Hacker News – https://thehackernews.com/2026/03/doj-disrupts-3-million-device-iot.html) ·
Help Net Security -(https://www.helpnetsecurity.com/2026/03/20/us-disrupts-iot-botnets-ddos-attacks-aisuru-kimwolf/) ·
The Register – (https://www.theregister.com/2026/03/20/botnet_disruption/) ·
BleepingComputer – https://www.bleepingcomputer.com/news/security/aisuru-kimwolf-jackskid-and-mossad-botnets-disrupted-in-joint-action/) ·
SecurityWeek – (https://www.securityweek.com/aisuru-and-kimwolf-ddos-botnets-disrupted-in-international-operation/) ·
FastNetMon – (https://fastnetmon.com/2026/03/20/aisuru-and-kimwolf-disrupted-but-the-botnet-cycle-continues/)