Aisuru: Unmasking the Cybercriminals Behind Record-Breaking DDoS Attacks
A massive botnet known as Aisuru has been wreaking havoc online, recently achieving a staggering 7.7 Tbps (terabits per second) distributed denial-of-service (DDoS) attack. This represents a significant escalation in the scale and sophistication of DDoS threats, and understanding who’s behind it is crucial for bolstering your online defenses. This article delves into the individuals allegedly operating Aisuru, their methods, and the ongoing efforts to identify and disrupt their activities.
The Rise of Aisuru and It’s Impact
Aisuru first gained notoriety in May 2025, when it unleashed a 6.3 Tbps attack against KrebsOnSecurity. This attack, one of the largest ever recorded, highlighted the botnet’s immense power and its operators’ willingness to deploy it. now, with a new record established at 7.7 Tbps, the threat posed by Aisuru is undeniable.
These attacks aren’t just about causing disruption; they represent a serious financial and operational risk to businesses and organizations. You need to understand the landscape to protect your infrastructure.
Identifying the key Players
XLab, a cybersecurity firm, has identified three individuals believed to be central to Aisuru’s operation. These roles are distinct and demonstrate a concerning level of association:
* Snow: Responsible for the core development of the Aisuru botnet itself.
* Tom: Focused on discovering new vulnerabilities to exploit and expand the botnet’s reach.
* Forky: Handles the sale and distribution of access to the botnet, essentially running a DDoS-for-hire service.
Forky: A Known Figure in the DDoS world
KrebsOnSecurity previously interviewed Forky in May 2025, revealing him to be a 21-year-old man based in Sao Paulo, Brazil. He’s been a prominent figure in the DDoS-for-hire scene since at least 2022.Law enforcement has repeatedly seized his DDoS-for-hire domains, yet he continues to operate.
[Image of Forky – as provided in the original text]
Interestingly, Forky also operates a “DDoS mitigation” service called Botshield. This raises questions about potential conflicts of interest and whether Botshield is truly protecting clients or simply providing a front for malicious activity. He’s been known to boast about Botshield successfully mitigating attacks against other DDoS-for-hire services.
A Shifting Narrative and Denials
During our previous interview, Forky admitted involvement in Aisuru’s development and marketing but vehemently denied participating in attacks launched by the botnet. When contacted again this month, he maintained this stance, claiming he’s also trying to uncover the real-life identities of the current aisuru operators.
However,this claim mirrors his response in the May interview. After promising to provide details, Forky ultimately offered nothing concrete. When pressed, he became defensive and terminated the interview.
“I’m not here to be threatened with ignorance as you are stressed,” Forky stated, adding that he’s being blamed for the new attacks, and attributing this to coverage on KrebsOnSecurity.
The mocking tribute: “Ethan J. Foltz”
A recent screenshot shared by XLab reveals Aisuru botmasters celebrating their record-breaking attack. Notably, one user has adopted the name “Ethan J. foltz.” This is a clear reference to the alleged operator of the “Rapper Bot” – a separate botnet - who was arrested and charged in august 2025.This suggests a degree of arrogance and a willingness to taunt law enforcement.
[Image of Aisuru botmasters screenshot – as provided in the original text]
What This Means for You
The Aisuru botnet represents a significant and evolving threat. Here’s what you can do to protect yourself:
* Invest in robust DDoS mitigation solutions: Don’t rely solely on your ISP’s protection. Consider dedicated DDoS mitigation services.
* Regularly assess your security posture: Identify and patch vulnerabilities in your systems.
* Implement rate limiting: This can help prevent your servers from being overwhelmed by
Worth a look