Desk live·
ForensicPost
Ransomware/Analysis/File 26-0325

One Botnet Was Removed and Twenty Took Its Place

Following the KimWolf disruption the ecosystem fragmented into more than twenty competing botnets, and daily active DDoS endpoints rose from roughly one million to eight or nine million over the year.

Constructed geometry · not a chart of case data
TargetGlobal botnet ecosystem
ActorMultiple
D. Kennedy10 min readConfidence: medium2 sources reviewed

Research describes the botnet ecosystem fragmenting into more than twenty competing operations following disruption, with daily active DDoS endpoints climbing from roughly one million to eight or nine million over the past year.

That is the uncomfortable companion to the takedown files in this section, and it is the second time this desk has had to file it after the stealer resilience case in 26-0626.

Fragmentation Is A Worse Outcome Than It Sounds

A single large botnet is a big problem with a single point of failure. Twenty competing operations built from the same device pool are a similar aggregate problem with twenty points of failure, each individually smaller and therefore less likely to attract a coordinated international operation.

Competition between them also drives capability. Operators are selling to the same customers, so they compete on capacity, resilience and evasion — which is how features like the ledger-based coordination in 26-0707 propagate.

The Device Pool Is The Constant

None of the disruptions addressed the underlying condition. The compromised routers and cameras remained connected, vulnerable and unpatched, and were recruited by whichever operation reached them next.

The endpoint growth from one million to eight or nine million did not require new techniques. It required the same technique applied to a device population that keeps growing and never gets cleaned.

What Would Actually Change The Number

Enforcement against operators does not reduce the pool. Reducing it needs device-level intervention: mandatory security support periods, automatic updates that survive end-of-support, and provider-level detection of compromised customer equipment.

Each of those is a regulatory or commercial decision rather than a policing one, and none is currently being taken at the scale the numbers require.

How we reported this

This is an analysis file built on published research, listed below. Endpoint counts are vendor-derived measurements with stated methodology limits. Corrections: corrections@forensicpost.com.

Sources
  1. One year later: the residential proxy botnet problem got bigger, not smallerNokia
  2. Aisuru botnet shifts from DDoS to residential proxiesKrebs on Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary