Cybersecurity Tech News

Feds Kill Botnets. Devices Stay Vulnerable.

IoT smart home device hub

The U.S. Department of Justice, working with authorities in Germany and Canada, announced Thursday that it had dismantled the command-and-control infrastructure behind four major botnets: Aisuru, KimWolf, JackSkid, and Mossad. Together, they had compromised more than three million devices worldwide, hundreds of thousands of them in the United States. The networks launched what prosecutors described as hundreds of thousands of DDoS attacks, including strikes against U.S. Department of Defense systems.

The largest single attack, a UDP flood linked to the Aisuru botnet in November 2025, peaked at 31.4 terabits per second. That is nearly six times the largest attack recorded in all of 2024, according to court documents cited by KrebsOnSecurity.

Two suspected operators have been identified. Canadian authorities targeted a 22-year-old man believed to be a core operator of the KimWolf botnet. German police said they searched the residence of a 15-year-old suspected of co-administering the networks. Extensive digital evidence was seized at both locations, according to German law enforcement statements reported by SecurityWeek.

A 22-year-old and a 15-year-old. Running networks capable of knocking Department of Defense systems offline.

How It Worked

The infected devices were overwhelmingly consumer IoT hardware. Webcams, digital video recorders, home routers, and according to Cloudflare’s technical summary, unauthorized Android TV streaming boxes. Cheap devices with weak or nonexistent security, sitting on home networks with factory-default passwords.

Aisuru first appeared in late 2024 as a Mirai variant, building on the infamous botnet code that was publicly leaked in 2016. By October 2025, the operators had spawned KimWolf, a variant with a new spreading mechanism that could reach devices hidden behind NAT on internal home networks. That is a meaningful technical escalation. Most IoT malware only catches devices directly exposed to the internet. KimWolf could reach the ones behind your router.

According to FastNetMon’s analysis, the combined attack capacity of the Aisuru and KimWolf infrastructure grew by over 700% in a single year.

The operators ran it as a business. Prosecutors said they sold access to the botnet through DDoS-for-hire services, according to The Register. Pay a fee, pick a target, and three million devices flood it with traffic. Some victims were extorted directly: pay up, or the attack continues.

The Takedown

The DOJ, operating through the U.S. Attorney’s Office for the District of Alaska, seized domains and backend systems used to coordinate the botnets. Nearly two dozen private companies participated, including Amazon Web Services, Google, and Cloudflare, according to CP24’s reporting. The cooperation cut off the command-and-control channels, which means the infected devices can no longer receive instructions from the operators.

This is the standard playbook for botnet takedowns. And it is exactly where the standard playbook falls short.

What Nobody Fixes

The three million devices are still compromised. Cutting the command-and-control channel does not clean the malware off a webcam or a router. It does not patch the vulnerability that let the device get infected in the first place. It does not change the factory-default password. Most owners of these devices do not know they were part of a botnet. Many will never know.

This is the cycle that has repeated since Mirai’s code went public a decade ago. Law enforcement takes down the infrastructure. The devices sit unpatched. New operators build new botnets from the same pool of vulnerable hardware. FastNetMon’s post-takedown analysis is blunt: “the botnet cycle continues.”

The IoT security problem is a manufacturing problem. Device makers ship products with known vulnerabilities, minimal update mechanisms, and default credentials that are publicly documented. There is no regulatory requirement in the United States forcing manufacturers to support these devices with security patches after sale. Some of the compromised devices in this operation probably cannot be updated at all.

The Timeline That Doesn’t Add Up

Here is the sequence. Read it slowly and ask yourself how these things happen simultaneously.

The Pentagon and the White House have spent the last two years warning that cyber warfare is the future of armed conflict. Chinese state hackers breached U.S. critical infrastructure through the Volt Typhoon campaign. Russian groups hit hospitals and water treatment plants. The Director of National Intelligence’s 2026 threat assessment put cyber at the top. Every appropriations hearing, every defense briefing, every national security speech says the same thing: the next war starts in cyberspace.

At the exact same time, the Trump administration gutted the agency built to defend against it. CISA is now operating at roughly 38% of its optimal staffing levels after waves of budget cuts and layoffs. The agency lost about a third of its workforce since January, according to TechCrunch. Programs dedicated to counter-ransomware efforts and secure software development have been gutted. Experienced specialists who spent years building relationships with critical infrastructure operators, water systems, power grids, healthcare networks, are gone.

Then in February, DOGE pushed to cut funding further. Career cybersecurity experts in regulated industries, people who understand the technical specifics of the sectors they protect, were removed from their positions. Not because they failed. Because the administration decided their roles were expendable.

And then this week, the DOJ announces a multinational takedown of botnets that hit Department of Defense systems. Built by teenagers. Using decade-old code. Targeting devices that have no security requirements because no regulation forces manufacturers to build secure IoT hardware.

That is the contradiction. You cannot claim cybersecurity is a national security priority while slashing the workforce, the funding, and the institutional knowledge that makes cybersecurity work. You cannot cut the experts out of regulated fields and then act surprised when the gaps they were covering get exploited. The DOJ can still mount an operation to take down command infrastructure. Good. But the agency responsible for helping organizations actually defend against the next attack is being hollowed out in real time.

Enforcement and prevention are moving in opposite directions. The government is spending money on the takedown and cutting money from the defense. That is not a strategy. That is a photo op.

The suspected architects of a network that hit the Pentagon are a college-age Canadian and a German teenager. They used a decade-old exploit framework against devices nobody bothered to secure, while the agency meant to prevent this was running at a third of capacity. The takedown worked. The underlying problem did not get one inch closer to being solved. And the people who could have been working on it were shown the door.