Full Breakdown
U.S. Disrupts Major Botnets Responsible for Record-Breaking Cyberattacks
3/21/2026, 10:55:22 AM
Overview of the Operation
On March 19, 2026, the U.S. Department of Justice announced a significant operation that dismantled four major botnets—Aisuru, KimWolf, JackSkid, and Mossad—responsible for infecting over 3 million devices worldwide, including hundreds of thousands in the United States. This coordinated effort involved collaboration with law enforcement agencies from Germany and Canada and targeted the command-and-control infrastructure used by these botnets to launch distributed denial-of-service (DDoS) attacks.
Details of the Botnets
The botnets primarily comprised Internet of Things (IoT) devices such as digital video recorders, webcams, and Wi-Fi routers. The Aisuru and KimWolf botnets, in particular, were noted for their scale and impact, with Aisuru alone being linked to record-breaking DDoS attacks that reached up to 30 terabits per second. These botnets operated on a "cybercrime-as-a-service" model, allowing other criminals to rent access to the compromised devices for launching their own attacks.
According to the Justice Department, the botnet operators executed hundreds of thousands of DDoS attacks against various targets, including the Department of Defense Information Network. The operation aimed to disrupt the communications tied to these botnets, prevent further infections, and reduce their capacity for future attacks.
Impact and Consequences
The operation's impact was significant, as it not only disrupted the botnets but also highlighted the vulnerabilities of IoT devices, which are often less secure than traditional computing devices. Victims of these attacks reported losses and cleanup costs amounting to tens of thousands of dollars. The Justice Department's statement indicated that the botnets had issued over 200,000 attack commands, with Aisuru being the most active.
Official Statements & Responses
U.S. Attorney Michael J. Heyman emphasized the commitment of the United States to safeguard critical internet infrastructure and combat cybercriminals. He stated, "The United States is steadfast in our commitment to safeguarding critical internet infrastructure and fighting the cybercriminals who jeopardize its security, wherever they might live." Kenneth DeChellis, a special agent in charge at the Department of Defense Investigative Service, noted, "Today’s disruption of four powerful botnets highlights our commitment to eliminate emerging cyber threats to the Department of Defense and its warfighters."
Criticism & Opposition
While the operation was largely praised, some experts have raised concerns about the ongoing threat posed by botnets and the need for more robust security measures for IoT devices. Cybersecurity journalist Brian Krebs, who has been targeted by these botnets, highlighted the persistent nature of such cyber threats and the challenges in fully eradicating them.
What's Next
Following this operation, ongoing investigations are expected to continue as authorities pursue individuals linked to the botnets. The collaboration between U.S., Canadian, and German law enforcement agencies may lead to further actions against cybercriminals operating in this space.
Verbatim Quotes
- “Today’s disruption of four powerful botnets highlights our commitment to eliminate emerging cyber threats to the Department of Defense and its warfighters,” — Kenneth DeChellis, Special Agent, Department of Defense Investigative Service
- “The United States is steadfast in our commitment to safeguarding critical internet infrastructure and fighting the cybercriminals who jeopardize its security, wherever they might live,” — Michael J. Heyman, U.S. Attorney
