Published On: September 17, 2026Categories: News

Scott Fisher – Massive DDoS Attacks on ISPs: A Look Into Kimwolf and Aisuru

Scott Fisher is Senior Principal Engineer at Team Cymru, where he focuses on threat intelligence, DDoS activity, botnets, and abuse of internet infrastructure. His work looks at how attackers use compromised devices, residential networks, and proxy infrastructure to launch or support attacks. He’s especially interested in the operational details of how these attacks behave on real networks, and what defenders can learn from that activity.

Kimwolf and Aisuru mark a new scale of volumetric DDoS aimed directly at ISPs. Built on millions of compromised IoT devices, they exploit the idle bandwidth provisioned for residential customers, at a volume that crushes networks well beyond the intended target.

At BalticNOG 2026, Scott will bring Team Cymru’s firsthand experience with these botnets to the stage with his talk, “Massive DDoS Attacks on ISPs: A Look Into Kimwolf and Aisuru.”

Where These Botnets Came From

Both Kimwolf and Aisuru trace back to Mirai, the IoT botnet that started with gamers running Minecraft servers before it evolved into scanning devices for hardcoded logins. Scott will walk through the Mirai family tree, from early variants like Persirai and Wicked through to Aisuru, which reuses Mirai’s scanner and loader architecture, and Kimwolf, a splinter from the Aisuru group built primarily on residential proxies pulled from infected streaming boxes.

How the Attacks Actually Operate

These botnets launch hundreds of attacks a day, each lasting only 30 to 60 seconds, with peak bandwidth reaching around 30 terabits per second. No ISP carries that much idle capacity. Scott will explain why: modern fiber plans hand residential users symmetric upload speeds in the multiple gigabits, and attackers are turning that unused upload bandwidth directly against the network. The attacks hit the victim and every autonomous system along the path, using multiple command-and-control servers that rotate daily and need no amplification at all.

Why Traditional Mitigation Falls Short

Scott will be direct about what doesn’t work. BGP Flowspec, RTBH, and commercial DDoS mitigation tools were not built for attacks at this speed and volume. Line-card ASICs saturate before software mitigation kicks in, TCAM tables run out trying to filter tens of thousands of source IPs, and even routing everything through a single provider like Cloudflare isn’t realistic when not everything can sit behind one ASN. Buying more bandwidth just turns into an arms race with rising costs.

What Actually Made a Difference

Null routing known command-and-control servers helped cut off egress bandwidth and kept transit costs down. But the real turning point was collaboration: small, trusted groups of stakeholders sharing intelligence under the Traffic Light Protocol. Team Cymru fed C2 IPs to community partners through its Nimbus threat monitor, worked directly with ISP peers to identify infrastructure, and coordinated with law enforcement on takedowns and arrests, the approach that has proven most effective against this generation of botnets.

Why You Shouldn’t Miss This Talk

If your network has felt the pressure of short, massive attacks that don’t fit the old playbook, this talk explains why, and what’s actually worked against them. Scott brings a firsthand account from a team that has been in the middle of the response, not a theoretical framework.

Whether you run a network, work in threat intelligence, or handle incident response, this talk gives you a clear picture of where this threat came from and what defenders can realistically do about it.

📅 When: 23-24 September 2026

📍 Where: BalticNOG 2026, Riga, Latvia

🔗 Don’t miss BalticNOG! Register today: https://balticnog.org/tickets/

Let others know – Share!