krebsonsecurity.com 10/29/2025, 1:25:33 AM · via preferred

Aisuru Botnet Shifts from DDoS to Residential Proxies

AISURU , the botnet once known for record-breaking DDoS, has been overhauled to rent hundreds of thousands of infected IoT devices to residential proxy providers, enabling cybercriminals to anonymise their traffic.

According to Netscout, in an executive summary on Aisuru, outbound attack traffic from compromised customer premise equipment has caused significant disruption to broadband networks, with DDoS activity previously clocking at 6.3 terabits per second in June and later showing capabilities approaching 30 terabits per second.

First identified in August 2024, Aisuru has spread to at least 700,000 IoT systems, including insecure routers and cameras, and is contributing to a boom in residential proxies used for large-scale data harvesting to fuel AI projects. Spur[.]us’s tracker estimates hundreds of millions of unique residential proxy IPs in the last 90 days, while proxy providers including Bright Data and Oxylabs have publicly contested some growth figures and warned of associated risks.

Separately, Reddit sued Oxylabs and other providers on 22 October over alleged mass-scraping of user content, highlighting ongoing legal scrutiny of the proxy ecosystem.

View full article

Article by CyberSIXT