Retail environments are absorbing the overwhelming majority of commerce-sector application-layer DDoS attacks, and the attack toolchains driving those incidents have grown significantly more complex. IoT botnets are now AI-assisted, capable of generating multi-terabyte attack volumes, and coordinated threat groups are combining these with logic exploits that target the decision-making layer of agentic AI systems embedded in commerce platforms. Security teams that sized their defenses against previous peak thresholds are now operating with a gap they may not yet have measured.
In this interview on TFiR, Steve Winterfeld, Advisory CISO at Akamai, breaks down the threat data behind the surge in retail-targeted attacks, explains how AI is being weaponized inside IoT botnets and agentic commerce systems, and walks through the specific fraud and exploitation patterns security teams need to be detecting in their logs today.
Guest: Steve Winterfeld, Advisory CISO at Akamai
Show: TFiR
Here is what every security practitioner and CISO protecting commerce infrastructure needs to know.
Technical Deep Dive
Q: How concentrated are DDoS attacks on retail within the commerce sector?
Steve Winterfeld, Advisory CISO at Akamai, citing Akamai’s threat visibility data, states that retail accounted for 84% of all commerce application-layer DDoS attacks. This concentration reflects retail’s exposure profile: high transaction volume, public-facing APIs, and complex third-party integrations that create a large and accessible attack surface compared to other commerce verticals.
“Retail accounted for 84% of all commerce application layered DDoS attacks.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is Turbo Mirai and how does AI change the IoT botnet threat?
Winterfeld identifies a threat group, the Iran-Iraq Hackmaster Group 313, as actively deploying a multi-vector attack approach that combines AI assistance with Mirai-based IoT botnets. Akamai is tracking this variant as Turbo Mirai. The addition of AI to the Mirai framework has driven attack peak sizes from gigabyte-scale to terabyte-scale and beyond, requiring organizations to reassess their DDoS defensive thresholds against these new maximums.
“There are variants of this that have really peaked the old gigabyte to terabyte to multiple terabyte size attacks that’s requiring CSOs to go relook their defensive capabilities.” — Steve Winterfeld, Advisory CISO, Akamai
Q: Why are IoT devices such an effective botnet resource for DDoS attacks against commerce sites?
Winterfeld frames the IoT botnet model simply: compromised consumer and industrial devices, including household appliances, are enrolled into a coordinated collection of systems that simultaneously direct traffic at a single target. The sheer volume of globally distributed IoT endpoints, most of which have weak or unmanaged security postures, provides attackers with an enormous and renewable pool of attack infrastructure that is difficult to block by origin.
“Your refrigerator is now part of a botnet which is just a collection of different systems and they’re all trying to attack one commerce site at the same time.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is Project Glasswing and how far have those vulnerabilities been operationalized?
Winterfeld references Project Glasswing as a framework involving the stacking of multiple vulnerabilities for compound exploitation. He notes that while the underlying vulnerabilities identified in that context are real, he has not observed widespread operationalization of them in active attacks by cybercriminals or activists. The gap between known vulnerability research and in-the-wild exploitation remains, but Winterfeld signals that AI’s growing role in attack tooling narrows that gap over time.
“A lot of them were real vulnerabilities, but they haven’t been used in the wild by cybercriminals or activists to cause damage or disruption.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How are attackers targeting AI agents embedded in commerce platforms?
Winterfeld explains that agentic AI systems in commerce, such as those handling credit card applications or customer service decisions, are being targeted at the logic layer rather than the network layer. Because agentic AI makes decisions autonomously and uses capability tokens to execute those decisions, attackers exploit the decision logic itself. Specific attack types include honoring expired promotional codes, authorizing fraudulent returns, and leaking proprietary inventory data.
“All of this is now logic exploits honoring expired promotional codes, authorizing fraudulent returns, leaking proprietary inventory data.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is token freeloading and why does it matter for agentic AI security?
Winterfeld describes tokens as the capability units that allow agentic AI systems to take action and access resources. Token freeloading refers to attackers abusing these tokens to consume or leverage AI capabilities without authorization. Akamai has documented this attack pattern in its malware research. As more commerce workflows delegate decision-making to AI agents, token security becomes a direct dependency of commerce fraud prevention.
“Tokens are those capabilities that let you leverage all this. We have a section on our malware talking about token freeloading.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What are the primary malware-driven threat patterns Akamai is tracking in retail and commerce today?
Winterfeld identifies credential theft leading to account takeover as the foundational malware-driven threat chain, followed by fraud enablement and persistent access as downstream consequences. Akamai functions as a Common Vulnerabilities and Exposures numbering authority, giving it research depth into how these attack chains are constructed and how they evolve. Winterfeld directs security teams to look within their logs and protective tooling for indicators of these patterns now.
“Credential theft leading to account takeover, fraud enablement, persistent access. Akamai is a common vulnerability, exposures, numbering authority. So we do a lot of this kind of research.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What should security teams be doing inside their environments right now given these evolving threats?
Winterfeld’s direct guidance is that security teams should be reviewing their logs and protective tooling for evidence of the attack patterns he describes, and that CISOs should re-examine their DDoS defensive thresholds given the new peak attack sizes enabled by AI-assisted botnets. He frames Akamai’s malware deep dive research as a reference resource for understanding specific indicators and behavioral signatures teams should be hunting for in their environments today.
“We talk in detail about some of this capability out there and what you should be looking for within your logs and within your protective organizations today.” — Steve Winterfeld, Advisory CISO, Akamai
Resources & Documentation
- Akamai DDoS Protection, Akamai’s platform for mitigating volumetric and application-layer DDoS attacks including IoT botnet-driven threats
- Akamai Security Research Blog, source for Akamai threat intelligence including Turbo Mirai analysis, token freeloading documentation, and malware deep dives
- CVE Program, the Common Vulnerabilities and Exposures numbering authority framework that Akamai participates in as a CVE Numbering Authority
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: Can you also talk about beyond agentic shoppers, what other trends are you seeing like DDoS and other traditional attacks as well?
Steve Winterfeld: So as you know, Akamai does a lot around DDoS protection and so we have a ton of insights, regional insights, industry insights, but within commerce, retail accounted for 84% of all commerce application layered DDoS attacks. There are groups out there like the Iran Iraq Hackmaster Group 313 that have been really focused on some of this stuff doing multi vector approach combining AI assisted Mirai Internet of Things botnet, we’re calling it Turbo Mirai. And there are variants of this that have really peaked the old gigabyte to terabyte to multiple terabyte size attacks that’s requiring CSOs to go relook their defensive capabilities with these new peak capabilities of all Internet of things. So this is the, the classic, you know, your refrigerator is now part of a botnet which is just a collection of different systems and they’re all trying to attack one commerce site at the same time. You know, and we talked a little bit about there, that you know, there’s AI capabilities being added in here. I haven’t seen a ton of these in the wilds. We talk about things like Project Glasswing, if you’ve heard about that, where they’re just stacking up all these vulnerabilities. I haven’t seen a ton of those vulnerabilities be operationalized. So a lot of them were real vulnerabilities, but they haven’t been used in the wild by cybercriminals or activists to cause damage or disruption. And so we think about this, but as AI gets in here, there’s this new vulnerable areas. A lot of us, when you go, there’s a chatbot there, can I help you? Well, they’re attacking those chat bots. If there’s agents, like let’s say you go in and you want to get a credit card from your, from your shopping store. A lot of that may now be handled by AI agents to make those decisions. Because again agentic AI is different than your traditional gen AI in that it makes decisions and then tokens. Tokens are those capabilities that let you leverage all this. In fact, we have a section on our malware talking about token freeloading. So you know, all of this is now logic exploits honoring expired promotional codes, authorizing fraudulent returns, leaking proprietary inventory data. There’s a lot of different types of attacks happening out here with this new AI capabilities beyond just those traditional ddos. And then we do a malware deep dive. You know, we talk about those traditional things. Credential theft leading to account takeover, fraud, enablement, persistent access. And akamai is a common vulnerability, exposures, numbering authority. So we do a lot of this kind of research, but we talk in detail about some of this capability out there and what you should be looking for within your logs and within your protective organizations today.





