Scott Fisher

Scott Fisher is a Senior Principal Engineer at Team Cymru, where he focuses on threat intelligence, DDoS activity, botnets, and abuse of Internet infrastructure. His work looks at how attackers use compromised devices, residential networks, and proxy infrastructure to launch or support attacks. He is especially interested in the practical, operational details of how these attacks behave on real networks and what defenders can learn from that activity.


Session

09-24
17:00
25min
Massive DDOS attacks on ISPs – A look into Kimwolf and Aisuru
Scott Fisher

Modern DDoS botnets have evolved far beyond the original Mirai model. Kimwolf and Aisuru leverage large populations of compromised IoT devices and residential connectivity to generate attacks reaching approximately 30 Tbps and billions of packets per second, often sending traffic directly from infected devices without relying on traditional amplification.

This presentation examines how these botnets evolved, how their command-and-control infrastructure operates, and the impact their attacks have not only on the targeted network, but also on every ASN carrying the traffic along the path. We will look at real-world mitigation approaches, including what failed, what helped, and why simply adding bandwidth or deploying traditional DDoS mitigation may not be enough at this scale. The presentation concludes with practical lessons from operators, including C2 disruption, trusted cross-network collaboration, and the role infrastructure takedowns and law-enforcement action can play in stopping attacks at their source.

ROOM ALFA