The US Justice Department with Canadian and German partners dismantled four IoT botnets controlling more than three million devices. Those botnets—Aisuru, Kimwolf, JackSkid and Mossad—were used to launch record-size DDoS attacks and to extort victims, including strikes against Defense Department addresses. Law enforcement seized command-and-control infrastructure; investigations continue and no US arrests were announced.
Part of the PlainSec briefing for 2026-03-22