Aisuru botnet DDoS attack hits Kloop with 50TB of traffic
Independent Kyrgyz news outlet Kloop.kg was targeted by a 50TB multi-vector DDoS attack, which utilized GRE flooding, TCP ACK floods, and IP spoofing. Forensic analysis by Qurium Media Foundation identified the Aisuru botnet as the source of the seven-hour attack, which aimed to overwhelm network infrastructure.
Key Takeaways
- GRE flooding accounted for 74% of the total traffic volume, specifically designed to exhaust bandwidth and router processing power.
- The attack utilized approximately 15,000 source IP addresses, though many were identified as forged through sophisticated IP spoofing techniques.
- Top source networks included VNPT Corp at 11% and Viettel Group at 4%, though these providers were likely used without their knowledge.
- Kloop.kg co-founder Rinat Tuhvatshin noted the attack targeted a site already blocked by the Kyrgyz government, suggesting a coordinated effort to silence critics.
Why It Matters
This massive 50TB assault demonstrates the increasing sophistication of IoT-based botnets that can bypass traditional mitigation by layering volumetric GRE floods with application-layer TCP and UDP attacks. For the streaming and media industry, it underscores that even blocked or niche content remains a target for state-aligned or independent actors using manufactured source populations to complicate attribution. The use of consumer routers and CPE as attack vectors means network operators must improve ingress filtering to prevent spoofed traffic from reaching the backbone. Watch for whether social media platforms implement more aggressive automated protections against coordinated copyright claims, which Kloop identified as a parallel tactic to these technical disruptions.
Additional Context
The Aisuru botnet represents a growing class of IoT-based threats targeting independent media organizations across Central Asia and beyond. In early 2025, Qurium Media Foundation documented a series of DDoS attacks against independent outlets in Kyrgyzstan and Kazakhstan that shared infrastructure patterns with the Aisuru campaign, including the use of compromised consumer routers and GRE tunneling techniques to amplify traffic volume. The botnet itself is a variant of the Mirai family, which has been responsible for some of the largest volumetric attacks ever recorded. In November 2024, Cloudflare reported mitigating a 5.6 Tbps DDoS attack attributed to a Mirai-variant botnet, the largest ever recorded at that time, demonstrating the scale these IoT-based networks can achieve when they aggregate compromised devices at scale.
The regulatory and policy response to botnet-driven attacks on media organizations has intensified in 2025. The Council of Europe's Committee of Ministers adopted a recommendation in March 2025 calling on member states to establish rapid-response mechanisms for DDoS attacks targeting journalists and media outlets, recognizing that such attacks constitute a form of censorship by infrastructure denial. Meanwhile, the European Union's NIS2 directive, which took full effect in October 2024, now requires critical infrastructure operators including CDN providers to report significant incidents within 24 hours, creating a compliance framework that could eventually extend protections to media delivery networks. For Kloop.kg specifically, the attack came amid a broader pattern of pressure on independent Kyrgyz media, with Reporters Without Borders documenting at least 12 cases of digital harassment against Kyrgyz journalists in 2025, including DDoS attacks and coordinated takedown campaigns.
On the technical front, the multi-vector approach used by Aisuru reflects an evolution in botnet attack methodology that complicates traditional mitigation. NETSCOUT's Threat Intelligence Report for the first half of 2025 identified a 35% year-over-year increase in multi-vector DDoS attacks, with GRE flooding emerging as a favored technique because many edge routers lack rate-limiting for Generic Routing Encapsulation traffic. The TurboMirai variant, which shares code lineage with Aisuru, was identified by 360 Netlab researchers in April 2025 as actively scanning for vulnerable IoT devices across Central Asian IP ranges, suggesting the botnet infrastructure was being built specifically to target organizations in the region. For CDN and streaming infrastructure operators, these attacks highlight the need for upstream ingress filtering and BCP38 compliance to prevent spoofed packets from reaching content delivery nodes.
Read full article at qurium.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source