Skip to content

Kimwolf

Kimwolf is an Android-focused IoT botnet, also tracked in connection with the AISURU/Aisuru lineage, that primarily compromises Android TV boxes and set-top devices.

Profile source: Mallory opens in a new tab

Kimwolf

Family profile

Kimwolf is an Android-focused IoT botnet, also tracked in connection with the AISURU/Aisuru lineage, that primarily compromises Android TV boxes and set-top devices. Active since at least 2024 and focused on Android targets from 2025, it abuses exposed, unauthenticated Android Debug Bridge services, commonly reached by tunneling through residential proxy networks into victim local networks. Supporting Android packages have masqueraded as system services and deployed embedded ELF payloads.

Kimwolf is principally used for distributed denial-of-service attacks and traffic relaying. Version 7 introduced browser-emulating HTTP/2 floods that reproduce Chrome-like request behavior and headers, alongside an ARM-optimized UDP flood and additional layer 3–7 attack methods. Its command-and-control architecture uses Ethereum Name Service resolution through public blockchain RPC services, a local proxy layer, and a Tor hidden-service fallback to improve resilience against infrastructure disruption. Version 7 removed scanning, exploitation, and brute-force functions from the main bot binary, consistent with separation of initial-access operations from DDoS execution and proxy-relay functions.

Observed activity also includes local scanning for Android Debug Bridge services and delivery of proxy payloads that turn compromised devices into TCP and UDP relays. This enables residential-proxy expansion and may facilitate reconnaissance or access to systems on victim local networks. Kimwolf was among botnets affected by multinational law-enforcement infrastructure disruption in March 2026. Public reporting links its infrastructure, payload characteristics, and operational behavior with Aisuru, although definitive operator attribution remains unconfirmed.

Capabilities

  • Ddos
  • Defense Evasion
  • Initial Access
  • Lateral Movement
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 14, 2026
Last activity
Sep 14, 2026
Feed role
C2
Host form
14 IP / 0 hostnames

Leading locations

  • NL10
  • RU2
  • GB1
  • LT1

Leading providers

  • DigitalOcean, LLC10
  • SYSECT D.O.O.2
  • Northern Data AG1
  • UAB Host Baltic1

Infrastructure traits

  • Hosting 14

Reported operators

Threat actors

3 named in public reporting
Dort

Menace émergente : Kimwolf/Dort # L’acteur individuel Dort a introduit une nouvelle menace en exploitant les proxies résidentiels eux-mêmes comme vecteur pour créer des botnets DDoS , atteignant un pic de ~400 000 IPs exploitées en un seul jour (février-mars 2026).

Aisuru-Kimwolf

Another variant, KimWolf, targets Android systems, including mobile phones and Smart TVs.

Snow

"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"

Exploited software

Vulnerabilities linked to Kimwolf

1 CVEs

MITRE ATT&CK

Kimwolf in ATT&CK

62 distinct techniques

Techniques

62 techniques
T1027 Obfuscated Files or Information T1090 Proxy T1071.001 Web Protocols T1059.004 Unix Shell T1105 Ingress Tool Transfer T1190 Exploit Public-Facing Application T1071.004 DNS T1046 Network Service Discovery T1498 Network Denial of Service T1071 Application Layer Protocol T1498.001 Direct Network Flood T1133 External Remote Services T1595 Active Scanning T1568 Dynamic Resolution T1090.003 Multi-hop Proxy T1110 Brute Force T1036 Masquerading T1008 Fallback Channels T1068 Exploitation for Privilege Escalation T1059 Command and Scripting Interpreter T1499.001 OS Exhaustion Flood T1499 Endpoint Denial of Service T1548 Abuse Elevation Control Mechanism T1496 Resource Hijacking T1584.005 Botnet T1588.001 Malware T1090.002 External Proxy T1210 Exploitation of Remote Services T1584.008 Network Devices T1001 Data Obfuscation T1083 File and Directory Discovery T1219 Remote Access Tools T1195 Supply Chain Compromise T1102.002 Bidirectional Communication T1573 Encrypted Channel T1021 Remote Services T1090.001 Internal Proxy T1562 Impair Defenses T1078 Valid Accounts T1584 Compromise Infrastructure T1583.005 Botnet T1570 Lateral Tool Transfer T1657 Financial Theft T1203 Exploitation for Client Execution T1070.004 File Deletion T1016 System Network Configuration Discovery T1016.001 Internet Connection Discovery T1195.002 Compromise Software Supply Chain T1571 Non-Standard Port T1568.002 Domain Generation Algorithms T1583 Acquire Infrastructure T1499.004 Application or System Exploitation T1021.004 SSH T1543.002 Systemd Service T1568.003 DNS Calculation T1480.002 Mutual Exclusion T1200 Hardware Additions T1070 Indicator Removal T1565.001 Stored Data Manipulation T1119 Automated Collection T1222 File and Directory Permissions Modification T1497.001 System Checks

Reporting

Research mentioning Kimwolf

Sep 4
Itpro

‘Attackers are steering their botnets with greater precision and control’: DDoS attack numbers might be dwindling, but they’re intensifying | IT Pro

A March multinational operation involving the United States, Canada, and Germany disrupted infrastructure supporting the Aisiru and Kimwolf botnets, contributing to a fall in the largest observed botnet from 13.5 million devices in Q1 2026 to 2.09 million in Q2. Link11 also reported a 42% decline in DDoS attacks in Europe during the first half of 2026, partly attributing the reduction to law-enforcement actions including Operation Eastwood and the shutdown of four IoT botnets. Attackers are compensating with more powerful and resilient campaigns: Link11 recorded peaks of 2.3 Tbit/s and 322 million packets per second, with 705 TB of cumulative malicious traffic, driven by super-botnets and hijacked cloud servers. Operators are increasingly dispersing traffic sources and adopting decentralized command infrastructure; the Aeternum and Void botnets use Polygon and Ethereum smart contracts for C2 distribution. DDoS surges are also being used to conceal SQL-injection and XSS probing, requiring defenses that combine continuous traffic inspection, behavioral detection, adaptive filtering, and application-layer monitoring.

Sep 4
Cyber Security News

Botnet Takedowns Are Working - But DDoS Operators Are Already Adapting

Sep 4
Cryptika

Botnet Takedowns Are Working - But DDoS Operators Are Already Adapting | Cryptika Cybersecurity

Sep 3
Securitysenses

Fewer attacks, more force: Link11's European Cyber Report finds new DDoS records for the first half of 2026 | SecuritySenses

Sep 2
Help Net Security

Global sinkhole operation ends Sality botnet’s 23-year run - Help Net Security

U.S., Bulgarian, Hungarian, and Romanian authorities, supported by CrowdStrike and the Shadowserver Foundation, disrupted the long-running Sality peer-to-peer botnet by seizing payload-hosting domains, dismantling control infrastructure, and sinkholing its super-peer network. The operation exploited Sality's unauthenticated peer-list protocol to redirect infected hosts away from operator-controlled infrastructure, cutting off delivery of new malware payloads and removing the botnet from the operators' control. Active since at least 2003, Sality infected more than 15,000 devices and spread by infecting Windows executables. CrowdStrike attributes the operation to SALTY SPIDER, a criminal group likely based in Russia's Republic of Bashkortostan; its infrastructure supported credential theft, spam, proxying, network exploitation, DDoS activity, and EggJagger cryptocurrency clipboard hijacking. Organizations should investigate UDP communications with 188.166.101[.]148, an indicator of Sality infection, because sinkholing prevents new payload delivery but does not remove malware from already compromised systems.

Sep 2
Mkd Cirt

Инфраструктурата на ботнетот Sality демонтирана во глобална координирана акција | MKD-CIRT | Национален центар за одговор на компјутерски инциденти

Sep 2
Security Week

23-Year-Old Sality P2P Botnet Disrupted - SecurityWeek

Sep 2
Malware News

Global public-private operation disrupts Sality botnet active for two decades - Malware News - Malware Analysis, News and Indicators

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.