2026-09-24 –, ROOM ALFA
Modern DDoS botnets have evolved far beyond the original Mirai model. Kimwolf and Aisuru leverage large populations of compromised IoT devices and residential connectivity to generate attacks reaching approximately 30 Tbps and billions of packets per second, often sending traffic directly from infected devices without relying on traditional amplification.
This presentation examines how these botnets evolved, how their command-and-control infrastructure operates, and the impact their attacks have not only on the targeted network, but also on every ASN carrying the traffic along the path. We will look at real-world mitigation approaches, including what failed, what helped, and why simply adding bandwidth or deploying traditional DDoS mitigation may not be enough at this scale. The presentation concludes with practical lessons from operators, including C2 disruption, trusted cross-network collaboration, and the role infrastructure takedowns and law-enforcement action can play in stopping attacks at their source.
Massive DDoS Attacks on ISPs: A Look into Kimwolf and Aisuru examines the newest generation of Mirai-descended botnets and the challenges they create for network operators.
Using Kimwolf and Aisuru as case studies, the session explores how enormous attacks originating directly from compromised devices can overwhelm not only their intended target but also upstream and peering networks. It covers the evolution and operation of these botnets, their impact on ISP infrastructure, where traditional mitigation techniques break down, and the approaches that have proven most useful—from blocking and null-routing C2 infrastructure to close collaboration between trusted network operators. Ultimately, the presentation asks a larger question: when attacks reach tens of terabits per second, what actually stops them?
Scott Fisher is a Senior Principal Engineer at Team Cymru, where he focuses on threat intelligence, DDoS activity, botnets, and abuse of Internet infrastructure. His work looks at how attackers use compromised devices, residential networks, and proxy infrastructure to launch or support attacks. He is especially interested in the practical, operational details of how these attacks behave on real networks and what defenders can learn from that activity.