Mirai Botnets Evolve Into Major DDoS and Proxy Abuse Threats
## Cybersecurity: Evolution of Mirai-Based Botnets
Cybersecurity: Evolution of Mirai-Based Botnets
Mirai-based botnets have advanced significantly from their origins as IoT malware into platforms capable of large-scale DDoS attacks and proxy abuse. Between July and December 2025, over 21,000 command-and-control (C2) servers were identified. A shift was observed in the use of these bots as residential proxies alongside traditional DDoS activities.
The increase in botnet activity coincided with larger DDoS campaigns. Data from Cloudflare in Q4 2025 reported a series of hyper-volumetric attacks, including a 31.4 Tbps incident linked to the Aisuru-Kimwolf botnet family.
Spamhaus reported a 26% increase in C2 activity in early 2025, followed by a 24% increase in the latter half of the year, indicating a resurgence in botnet operations.
Technical Specifications and Developments
Mirai, initially detected in 2016, targets internet-connected devices running lightweight Linux systems protected by default or weak credentials. Once compromised, these devices become part of a botnet capable of high-volume UDP, TCP, and application-layer floods.
Mirai-based botnets have advanced significantly from their origins as IoT malware into platforms capable of large-scale DDoS attacks and proxy abuse.
The public release of Mirai’s source code led to numerous variants, adding new exploits, CPU architectures, and evasion features while preserving core functionalities. Satori, a well-known Mirai variant, was first detected in 2017. It exploited remote code execution vulnerabilities in home and small-office routers, deploying scripts for broad infection.
Recent developments saw the Aisuru and Kimwolf families utilizing Mirai-style botnets for extreme-scale DDoS operations and as rentable residential proxy networks. Cloudflare and security researchers linked these families to significant DDoS attacks, employing randomized packet characteristics to bypass filters.
Kimwolf, an Android-focused Aisuru variant, has been involved in abusing residential proxy providers to access internal networks, infecting smart devices, and facilitating fraud through underground channels.
Countermeasures and Ongoing Challenges
Efforts to curb botnet activity include U.S. initiatives targeting IoT DDoS botnets' C2 infrastructure and collaborations to disrupt domains marketing residential proxies. Despite these efforts, Mirai-based ecosystems continue to thrive due to unpatched routers and insecure devices. Ongoing vigilance in device security and monitoring for anomalous traffic patterns remains crucial.
Based on reporting by GBHackers.
