US, Germany, and Canada take down massive global botnet networks infecting over 3 million devices
The United States Department of Justice announced on March 19, 2026, that it had cooperated with Germany and Canada to dismantle four major botnets — Aisuru, KimWolf, JackSkid, and Mossad — that infected more than three million devices across the globe. These malicious networks were primarily used for launching distributed denial-of-service (DDoS) attacks, some of which targeted websites belonging to the US Department of Defense. Most compromised devices belonged to the Internet of Things (IoT), including webcams, DVRs, and Wi-Fi routers, which are often vulnerable because of weak or outdated security settings. According to the Justice Department, operators of these botnets conducted hundreds of thousands of DDoS attacks, disrupting online services and even demanding ransom from affected organizations. The coordinated international operation, carried out simultaneously in the US, Germany, and Canada, aimed to disable both the infrastructure supporting these attacks and to identify individuals behind the networks. Nearly two dozen major tech companies assisted in the takedown, including Amazon Web Services, Google, PayPal, and Nokia, alongside Europol’s PowerOff team, which has led anti-DDoS enforcement efforts since 2017. Kenneth DeChellis, a special agent at the Department of Defense Investigative Service, stated that this disruption demonstrates the government’s continued commitment to neutralize emerging cyber threats targeting US defense systems and critical infrastructure.
