AIRASHI Botnet Unleashes DDoS Chaos: Is Your Router Next?
Threat actors are exploiting a zero-day vulnerability in Cambium Networks cnPilot routers to deploy the AIRASHI botnet for DDoS attacks. AIRASHI, a variant of AISURU, has been active since June 2024, with compromised devices mainly in Brazil, Russia, Vietnam, and Indonesia. It’s like a cyber game of whack-a-mole—only less fun.

Hot Take:
Apparently, Cambium Networks cnPilot routers have become the new playground for threat actors who are living their best botnet life and throwing some serious DDoS parties. The AIRASHI botnet variant (a.k.a. the rowdy cousin of AISURU) has been causing chaos across the globe, and let’s be real, it’s probably not going to stop anytime soon. Time to batten down the hatches, folks, because these cyber pirates are sailing the high seas of your network!
Key Points:
- Unspecified zero-day vulnerability in Cambium Networks cnPilot routers exploited by AIRASHI botnet.
- AIRASHI is a variant of the AISURU botnet, infamous for DDoS attacks.
- Culprits are using multiple vulnerabilities, including those linked to AVTECH, LILIN, and Shenzhen TVT devices.
- Compromised devices are widely spread in Brazil, Russia, Vietnam, and Indonesia.
- The botnet is evolving with new features like proxyware functionality and using complex encryption algorithms for communication.