Inside Today’s Botnets – Changing Supply Chain Behind the Terabit Scale Attacks

Outi Maria Pietilanaho

October 2, 2026

Home ‣ FastNetMon Blog ‣ Inside Today’s Botnets – Changing Supply Chain Behind the Terabit Scale Attacks

This article is based on the presentation “Tracking Today’s Botnets — Threat Intel & Lessons to Defend Against DDoS”, presented by FastNetMon’s Outi Maria Pietilänaho at NOG.HR Meetup 7 in Zagreb in September 2026. The talk focused on what recent DDoS data tells us about the infrastructure behind the attacks: where the capacity is coming from, how botnets are being built, and how the ecosystem is responding to disruption.

From Denial of Service to the 1 Tbps DDoS era

Denial of service is almost as old as the public Internet. The 1988 Morris worm was not a modern DDoS botnet, but its runaway propagation demonstrated how quickly distributed systems could exhaust shared resources. By the end of the 1990s, coordinated DDoS tooling had appeared: compromised machines were organised behind handlers and instructed to flood a target together. Researchers were already documenting hundreds of systems participating in coordinated attacks around the turn of the millennium.

For most network operators, though, the more relevant history is much more recent.

A few hundred gigabits per second once qualified as an exceptional DDoS event. The emergence of Mirai moved that ceiling around 2015 by showing what could happen when hundreds of thousands of cheap IoT devices were recruited at Internet scale. The original Mirai research tracked the botnet to a peak of roughly 600,000 infections, built largely through Internet-wide scanning and weak or default credentials.

Then the numbers began moving in a completely different pace.

In October 2024, Cloudflare reported a 5.6 Tbps UDP attack, generated by a Mirai variant. It lasted only 80 seconds and involved more than 13,000 IoT sources. And then, 2025 came, with almost absurd attack volume growth. 7.3 Tbps. 11.5 Tbps. 29.7 Tbps. By Q3 2026, the infamous Aisuru botnet was routinely producing attacks above 1 Tbps and 1 Bpps, and by the end of the year, the public bandwidth record had reached 31.4 Tbps.

And to be frank, the most telling number may not be the record at all. In the first half of 2026, Cloudflare reported to have mitigated 935 network-layer DDoS attacks above 1 Tbps. Between Q1 and Q2, the number of such attacks increased 519%. We have, effectively, entered the 1 Tbps era. Terabit traffic is no longer interesting only because somebody broke a record. It has become a repeatable, common attack class, and this is the development where we should pay attention to, not necessarily the peak volumes and headlines.

Pie chart illustrating the exponential growth in DDoS attack volumes. List of reported attacks is not exhaustive.

But traffic does not appear from nowhere. If attack capacity has increased by this much, there must be an underlying increase in available infrastructure. This is what we are looking into next.

How many bots in a net?

For years, a large DDoS botnet generally meant tens or hundreds of thousands of sources. Mirai has been notorious precisely because it could reach hundreds of thousands of vulnerable devices.

Through 2022, 2023 and 2024, the largest observed botnet populations were still broadly in that spectrum of several hundreds of thousands of compromised devices.

Then, in 2025, things changed.

Qrator first detected one very large bot population in March 2025 at 1.33 million devices. By Q1 2026, it had grown to 13.5 million.

Those figures need some caution. A source IP, an active attacking endpoint and an infected physical device are not necessarily the same thing. DHCP churn, NAT, CGNAT and rotating residential addresses make botnet measurement inherently messy. Different vendors also have different visibility.

But the exact census is less important than the order-of-magnitude change. Within a short period, researchers went from discussing populations in the hundreds of thousands to populations in the millions.

Estimate number of bots in the largest botnets according to mainstream threat intelligence. For the purpose of illustrating scale - exact bot count in a botnet is complicated to achieve.

The basic mechanism behind IoT botnets was not mysterious. Mirai had already shown how effectively the Internet itself could serve as a recruitment pool.

Its bots scanned addresses looking for reachable devices, attempted known credentials, infected successful targets and then repeated the process. Later families added CVEs, new device classes and better persistence, but the underlying model remained recognisable:

find something exposed on the Internet, compromise it, and add it to the botnet.

That model survived for surprisingly long.

And from a threat-intelligence perspective, it had a useful characteristic: the source often explained itself. If a particular IP address appeared in DDoS telemetry, researchers could scan it and frequently find a router, camera, DVR or exposed service that plausibly explained the infection.

That was roughly the picture Nokia Deepfield says it saw through 2024. Its DDoS source intelligence often mapped neatly onto identifiable vulnerable devices or services.

Then, in 2025, things stopped making sense in the way we were used to. But, before getting to the why, it is useful to look at the entire machinery.

How does a DDoS botnet work?

A DDoS botnet can be simplified into five stages: recruit, control, attack, impact, persist.

First, the operator needs devices. That is recruitment: exploiting them, stealing them, renting access to them, or otherwise bringing them under control.

Those devices then need a command path. C2 tells them what to attack, which vector to use, when to start and when to stop. Modern operators may rotate infrastructure, distribute tasks across different bot populations and change vectors during a campaign.

At launch, the botnet converts that control into traffic: UDP floods, TCP floods, application requests or combinations of several vectors.

The impact depends on where the target runs out of resources. Sometimes it is bandwidth. Sometimes packet processing. Sometimes connection state or the application itself.

And after the attack stops, the useful bots normally remain. The operator can reuse them tomorrow.

Each part of this chain matters, but the recent step-change in botnet scale makes one stage particularly interesting:

The bot recruitment. And particularly, how did the pool of recruitable infrastructure suddenly become so much larger?

What changed in the botnet recruitment?

The old model is easy to draw.

An operator scans the Internet. A router answers. A camera exposes an old service. A DVR has default credentials. A CPE device runs a vulnerable firmware version.

Exploit the vulnerability, install the bot, enroll it into C2. Repeat.

Around 2025, we started seeing attack sources that did not fit that model.

Volumetric DDoS was arriving from ordinary-looking residential IP addresses. Researchers looked at those addresses and could not find the expected vulnerable Internet-facing device. No obvious camera, router or exposed service explained why that subscriber was suddenly generating attack traffic.

The common feature was residential proxy infrastructure.

Residential proxy networks themselves are not new. They provide a customer with traffic egress through a real consumer connection rather than a data-centre address. There are legitimate reasons to buy that service, and many dubious ones.

Crucially, though, buying residential proxy service does not normally mean buying the device itself. Proxy access is not root access.

What botnet operators discovered was that some proxy implementations could provide a route further into the endpoint: An attacker could buy access through the proxy network and, because of weaknesses in how the proxy software handled local destinations, reach an Android Debug Bridge service on the underlying device. The endpoint might be safely hidden behind NAT or CGNAT from the public Internet, yet reachable from inside the proxy overlay. From there, the attacker could gain control and install malware.

The recruitment path had changed from:

scan the Internet → find device → compromise device

to something closer to:

buy proxy access → reach device through the proxy network → exploit locally reachable service → install bot

That is a profound difference for both attackers and defenders.

The public IP no longer needs to expose the vulnerability. Internet-wide scanning may tell you very little about how the endpoint was compromised.

This also changes the size of the pool.

Some researchers have described the conventional active DDoS population it had been tracking as roughly one million bots. The residential proxy ecosystem represented an estimated 100–200 million devices.

It is useful to make the distinction though: those are not 100–200 million infected bots. They are potentially reachable endpoints.

But that is exactly why the number is important. Attackers no longer need every device in that pool to be compromised. They need a repeatable path into a critical mass of exploitable devices.

When the available pool grows by two orders of magnitude, even a low conversion rate can create a very large botnet.

From building the botnet to buying the supply

This is where the change becomes economic rather than purely technical.

The traditional botmaster had to discover its own inventory. Scanning, exploitation and recruitment were part of building the botnet. Residential proxy networks introduce an intermediary.

Deepfield described operators buying proxy access and using it to reach vulnerable devices. In the channels researchers were observing, acquiring access paths towards roughly 100,000 devices could reportedly cost only $10–15.

That does not mean $15 buys 100,000 infected bots. It buys access from which some portion of those devices may become exploitable. But the effect on botnet resilience is obvious.

If defenders eliminate 100,000 bots and replacing them requires the operator to rediscover 100,000 vulnerable hosts across the public Internet, the disruption has a real rebuilding cost.

If the operator can go back to an access market, buy another population and repeat the compromise process for a very nominal price, replacement becomes much easier.

Next interesting observation is that DDoS is only one way to monetise these devices.

There are several instances where Kimwolf has been observed to use compromised endpoints both for volumetric DDoS and proxying. The botnet could enter through one proxy service, install another proxy component and sell the residential connection again. The same infrastructure was also associated with credential abuse, while other families added LAN scanning that could support reconnaissance or lateral movement.

So there is a broader economy competing for these endpoints. A compromised Android box can be DDoS capacity, a residential exit node, credential-abuse infrastructure and a foothold inside a private network.

The market incentive does not disappear when one DDoS service does. And once the access route became understood, other operators piled in. Currently, we can observe several botnet operators competing for the same devices, building methodologies for eliminating competing bots and moats for being eliminated. A botnet war happening inside a device while the owner is clueless of anything illegitimate happening.

What about take downs?

None of this means law-enforcement disruption has stopped working.

In March 2026, US authorities joined simultaneous actions in Canada and Germany against infrastructure used by Aisuru, KimWolf, JackSkid and others. Domains, servers and other infrastructure were targeted; the four botnets collectively controlled millions of devices.

A wider PowerOFF action the following month targeted the DDoS-for-hire market itself: authorities in 21 countries acted against more than 75,000 identified users, took down 53 domains and executed 25 search warrants.

The impact is visible, and had tangible impacts. Qrator's largest observed botnet population fell from 13.5 million in Q1 2026 to 2.09 million in Q2. Nokia Deepfield's research team says the disruption of Kimwolf's original DDoS C2 worked: that operation is no longer active at its previous scale.

But the replacement ecosystem remained.

That forces takedowns to look beyond a single C2 server. Which dependency is actually difficult for the operator to replace? The hosting? The command path? The proxy provider? The access broker? The vulnerable software? The operator themselves?

Attackers are simultaneously trying to make those dependencies less obvious.

Qrator found Aeternum storing C2 instructions in smart contracts on Polygon. Soon afterwards it documented Void, an unrelated Rust botnet using Ethereum smart contracts for the same basic purpose: infected hosts retrieve commands through public blockchain RPC infrastructure rather than depending entirely on a conventional domain and server.

The DDoS packets do not travel through Ethereum. The blockchain is being used to make a small but critical part of the control plane harder to locate and seize.

And the barrier to building this infrastructure may be falling as well.

Palo Alto Networks' Unit 42 recently analysed TuxBot v3, a multi-architecture IoT botnet framework whose developer relied heavily on an LLM to generate code, port exploits and build parts of the C2. The result was imperfect — Unit 42 found broken components, hallucinated cryptography and even AI safety warnings left in the source — but the core scanning, credential brute-forcing, persistence, C2 and DDoS functions worked. The framework compiled for 17 architectures and included automated testing infrastructure.

It would be too strong to say that LLMs have made sophisticated botnet engineering trivial. TuxBot itself demonstrates the opposite: generated code still failed in revealing ways.

What it does show is that one developer can assemble a surprisingly ambitious framework with much more machine assistance than was available a few years ago. That lowers the engineering barrier for the next generation of operators, even if it does not eliminate it.

For defenders, this means the landscape is moving at several layers at once: recruitment is becoming commoditised, C2 is becoming more seizure-resistant, and tooling is becoming easier to assemble.

We're all part of the problem - and solution too!

There is one final change that matters directly to operators.

DDoS has traditionally been discussed from the receiving side: detect the traffic, divert it, scrub it, filter it.

Residential botnets make the other end of the attack increasingly difficult to ignore.

We are already seeing large concentrations of compromised residential devices creating availability problems inside the originating ISP itself, particularly in Latin America. The impact can propagate into aggregation, ingress and transit infrastructure even when that network is not the attack target. And as we discussed, the problem is very tangible when with millions of available devices, a botnet operator does not even need to activate the entire population.

This makes outbound DDoS visibility a network-engineering issue, not merely an abuse-desk concern.

Access networks have a direct incentive to identify abnormal outbound floods, compromised subscriber populations and botnet C2 traffic before it consumes their own capacity or reaches somebody else's.

It also makes DDoS defense increasingly collective. Target networks, access ISPs, transit providers, mitigation networks, device vendors, proxy operators, researchers and law enforcement all see different pieces of the same system.

There is no single filter that fixes the current botnet problem. There is no takedown that permanently removes the economic incentive. And there is no reason to expect the recent growth in capacity to reverse on its own.

What we have seen over the past 12–18 months is an abrupt expansion of both botnet capacity and botnet supply. The important development is not simply that attacks reached 30 Tbps. It is that the infrastructure behind them became easier to source, easier to replace and valuable for more than DDoS alone.

The answer will have to evolve in the same way: better source-side visibility, faster automated mitigation, intelligence sharing, device remediation, pressure on abusive access markets and coordinated law-enforcement action against the parts of the value chain that are genuinely difficult for attackers to rebuild.

There is no silver bullet here.

But network operators have always been unusually good at solving problems that cross organisational boundaries. Today’s botnet ecosystem gives the community another one.