The takedown and what it revealed

Law enforcement agencies across the US, Canada and Germany have successfully dismantled the infrastructure supporting four major botnets that collectively compromised over 3 million devices worldwide. The networks—Aisuru, KimWolf, JackSkid and Mossad—orchestrated hundreds of thousands of distributed denial-of-service attacks, targeting systems including those operated by the US Department of Defense. Industry observers have called this operation one of the most significant botnet takedowns on record.

The scale of the threat these botnets posed was extraordinary. Combined, they could generate attack traffic surpassing 30 terabits per second. A single coordinated assault by Aisuru and Kimwolf in November reached approximately 31.4 Tbps—nearly triple the magnitude of any previously documented attack.

The botnets' operational method exploited a fundamental weakness in consumer IoT infrastructure. By infecting Wi-Fi-connected household devices—routers, webcams, digital video recorders, smart TVs and set-top boxes—attackers created what security researchers term a "residential proxy" network. This approach allowed malicious traffic to originate from ordinary homes, making attacks difficult to attribute and enabling them to evade conventional security filters.

Why the threat persists

Although authorities seized the domains and backend servers directing the botnets, the underlying vulnerability remains unresolved. As IoT For All noted, "The four botnets spread almost exclusively through internet-connected consumer devices — routers, webcams, digital video recorders, smart TVs, set-top boxes — the kind of hardware that gets plugged in once and forgotten. These devices are routinely shipped with weak default credentials, rarely receive firmware updates, and are almost never monitored by their owners."

This combination of factors creates ideal conditions for botnet recruitment. Manufacturers can ship devices with minimal security hardening, knowing that most consumers will never update firmware or change default passwords. The compromised hardware remains online indefinitely, available for conscription into future attack networks. As the analysis concludes, "Hundreds of millions of poorly secured IoT devices remain online, running outdated firmware or factory-default passwords, permanently available for conscription [without their owners even knowing]. Until device manufacturers are held to higher security standards — or consumers demand them — the recruitment pool for the next Aisuru is already out there, plugged into the wall and waiting."

The botnet operators also demonstrated the commercial viability of their model by running a cybercrime-as-a-service operation, renting access to their hijacked infrastructure to other criminal actors.

Regulatory responses taking shape

United States

The Federal Communications Commission recently announced a sweeping new mandate: all consumer-grade routers manufactured outside the US will face a sales ban unless suppliers obtain Conditional Approval from the Department of War or Department of Homeland Security. The restriction applies to new devices only; existing routers and those already approved by the FCC may continue operating and being sold.

The definition of "foreign-produced" encompasses devices assembled overseas for American brands as well as those with supply chains involving countries including China, Taiwan and Vietnam—essentially capturing nearly all household routers currently on the market. The FCC justified the decision by citing an Executive Branch determination that foreign-manufactured routers create a "supply chain vulnerability that could disrupt the US economy, critical infrastructure and national defense" and pose severe cybersecurity risks.

Currently, the US relies on a voluntary Cyber Trust Mark program for IoT devices alongside industry-specific regulations and sector-level mandates that typically encourage collaboration rather than enforce strict requirements. The US and EU agreed in 2023 to develop the EU-US Joint Cyber Safe Products Action Plan to align their approaches and work toward mutual recognition of standards.

United Kingdom

The UK introduced what officials describe as "the world's first legislation on the cyber security of consumer connectable products: the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and the PSTI Regulations 2023," which took effect on 29 April 2024. The legislation directly addresses the vulnerabilities that enabled the botnets through several mechanisms.

Manufacturers must eliminate default passwords—prohibiting universal, hardcoded or easily guessable credentials such as "admin" or "12345." They must establish a public contact point for security researchers to report vulnerabilities before exploitation occurs. Device makers must also disclose the minimum period during which they will provide security updates, helping consumers make more informed purchasing decisions.

Non-compliance carries substantial penalties: fines reaching £10 million or 4% of qualifying worldwide revenue. Japan and Singapore are now harmonising their approaches with the UK framework, as reported to Parliament in November 2025.

European Union

The EU's Cyber Resilience Act (CRA), building on the 2020 EU Cybersecurity Strategy and EU Security Union Strategy, establishes mandatory cybersecurity requirements across the entire product lifecycle. The legislation applies to manufacturers of consumer devices ranging from baby monitors to smart watches, covering planning, design, development and maintenance.

Manufacturers must address vulnerabilities throughout their products' operational lives. Certain high-risk products may require third-party assessment by a notified body before market entry. Compliant products will display CE marking, with national market surveillance authorities responsible for enforcement.

The CRA entered into force on 10 December 2024, but the main obligations will not apply until 11 December 2027. Reporting obligations commence on 11 September 2026. Given the scale and immediacy of the threat, that 2027 deadline represents a significant window of vulnerability.

Beyond Wi-Fi: Expanding attack surfaces

Wi-Fi remains the dominant IoT connectivity technology, accounting for 32% of all IoT connections, with its share expanding through three trends: adoption of low-power Wi-Fi standards like Wi-Fi 6 with Target Wake Time and extended sleep modes enabling battery-powered devices; enterprise equipment upgrades to Wi-Fi 6E and Wi-Fi 7 improving throughput and reliability; and Wi-Fi HaLow (802.11ah) gaining traction below 1GHz for long-range, low-power industrial and outdoor applications.

However, Wi-Fi represents only one attack surface. "Bluetooth and IoT technologies have quietly become one of the most overlooked attack surfaces in modern cybersecurity," according to analysis published in December. Many IoT ecosystems rely on wireless protocols including Bluetooth, Zigbee, Z-Wave and proprietary radio-frequency implementations that "often assume a trusted environment and lack robust authentication, encryption, or replay protection," operating for years with unchanged firmware and credentials.

Once compromised, IoT devices are rarely cleaned or reinstalled. They persist as long-term footholds within networks, enabling attackers to pivot laterally, exfiltrate data or maintain persistence without engaging traditional endpoints—often evading perimeter defences entirely.

The timeline challenge

IoT device forecasts have shifted substantially since the early 2010s. The prediction of 50 billion connected devices by 2020 has been pushed to 2035, with IoT Analytics expecting 39 billion devices by 2030, representing a compound annual growth rate of 13.2% between the end of 2025 and that date. The rapid expansion of IoT deployment, combined with the delayed implementation of major regulatory frameworks, leaves a critical period where billions of vulnerable devices will remain in operation without mandatory security standards.

Source: Mobile Europe