Skip to content

Kimwolf

KimWolf is a large Android- and IoT-focused DDoS botnet operated as a cybercrime-as-a-service platform.

Profile source: Mallory opens in a new tab

Kimwolf

Family profile

KimWolf is a large Android- and IoT-focused DDoS botnet operated as a cybercrime-as-a-service platform. It has been described as a variant of AISURU and has been linked to the online persona Dort, with law-enforcement actions in 2026 targeting both its infrastructure and its alleged operator. The botnet has been associated with very large volumetric attacks, including record-scale multi-terabit DDoS activity, and with more than 25,000 attack commands issued against targets worldwide, including systems associated with the U.S. Department of Defense Information Network.

KimWolf primarily compromises Android-based consumer and embedded devices, especially Android TV boxes, streaming devices, webcams, digital photo frames, and other internet-connected equipment. Reporting also ties its growth to abuse of residential proxy networks, where operators tunneled through proxy endpoints into local networks and infected additional Android devices behind victim firewalls. Some research further links KimWolf infections to exposed Android Debug Bridge services and to supply-chain style exposure involving low-cost Android TV hardware. Infected devices have been observed at very large scale, with public estimates ranging from more than one million to nearly two million compromised systems.

The malware’s functionality centers on distributed denial-of-service operations, but reported capabilities also include proxy forwarding, reverse-shell style remote access, and file-management features. Researchers have additionally documented efforts to harden its command-and-control resilience, including use of DNS over TLS, cryptographic authentication of commands, and blockchain-based naming mechanisms such as ENS-related infrastructure in some variants or related operations. KimWolf has been characterized as highly adaptable and resilient, with ties to the broader ecosystem of malicious residential proxy and IoT botnet activity.

KimWolf has been associated with attacks against enterprises, public-sector networks, and critical internet-facing infrastructure. It is part of a broader cluster of botnets disrupted alongside AISURU, JackSkid, and Mossad in multinational operations during 2026. The botnet is notable both for its scale and for its use of compromised consumer devices and residential-network access as a foundation for high-impact DDoS-for-hire services.

Capabilities

  • Ddos
  • Post Exploitation
  • Scanning
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Jul 31, 2026
Feed role
C2
Host form
10 IP / 0 hostnames

Leading locations

  • NL10

Leading providers

  • DigitalOcean, LLC10

Infrastructure traits

  • Hosting 10

Reported operators

Threat actors

3 named in public reporting
Dort

Menace émergente : Kimwolf/Dort # L’acteur individuel Dort a introduit une nouvelle menace en exploitant les proxies résidentiels eux-mêmes comme vecteur pour créer des botnets DDoS , atteignant un pic de ~400 000 IPs exploitées en un seul jour (février-mars 2026).

Aisuru-Kimwolf

Another variant, KimWolf, targets Android systems, including mobile phones and Smart TVs.

Snow

"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"

MITRE ATT&CK

Kimwolf in ATT&CK

57 distinct techniques

Techniques

57 techniques
T1496 Resource Hijacking T1584.005 Botnet T1588.001 Malware T1090.002 External Proxy T1499 Endpoint Denial of Service T1071 Application Layer Protocol T1568 Dynamic Resolution T1498 Network Denial of Service T1210 Exploitation of Remote Services T1090 Proxy T1190 Exploit Public-Facing Application T1584.008 Network Devices T1001 Data Obfuscation T1083 File and Directory Discovery T1090.003 Multi-hop Proxy T1219 Remote Access Tools T1071.004 DNS T1133 External Remote Services T1195 Supply Chain Compromise T1102.002 Bidirectional Communication T1059 Command and Scripting Interpreter T1573 Encrypted Channel T1021 Remote Services T1046 Network Service Discovery T1090.001 Internal Proxy T1562 Impair Defenses T1078 Valid Accounts T1105 Ingress Tool Transfer T1059.004 Unix Shell T1584 Compromise Infrastructure T1498.001 Direct Network Flood T1583.005 Botnet T1570 Lateral Tool Transfer T1657 Financial Theft T1203 Exploitation for Client Execution T1070.004 File Deletion T1016 System Network Configuration Discovery T1036 Masquerading T1595 Active Scanning T1016.001 Internet Connection Discovery T1027 Obfuscated Files or Information T1195.002 Compromise Software Supply Chain T1571 Non-Standard Port T1568.002 Domain Generation Algorithms T1583 Acquire Infrastructure T1499.004 Application or System Exploitation T1021.004 SSH T1543.002 Systemd Service T1568.003 DNS Calculation T1480.002 Mutual Exclusion T1200 Hardware Additions T1070 Indicator Removal T1071.001 Web Protocols T1565.001 Stored Data Manipulation T1119 Automated Collection T1222 File and Directory Permissions Modification T1497.001 System Checks

Reporting

Research mentioning Kimwolf

Jul 28
Cyberveille

Écosystème de proxies résidentiels malveillants : 20 millions d'IPs/jour dans 30+ botnets | CyberVeille

Black Lotus Labs reported a sprawling malicious residential proxy ecosystem built from compromised IoT and SOHO routers, Android devices, and Android TV boxes, tracking nearly 20 million distinct IPs per day across 30+ botnet clusters. The research identified major services and botnets including IPIDEA, Jaguar, Kookeey, NetNut/Popa, G3Proxy, NSOCKS/Ngioweb, and ASOCKS/Nexusnet, and said many operators both maintain their own botnets and resell access to other infected devices. Lumen said more than 20 of the clusters regularly exceed 100,000 daily victims, with roughly half of the tracked malicious proxy botnets operated by Chinese actors and many services excluding mainland China from their proxy pools. Separate analysis of the low-cost Android-based Magcubic HY300 Pro+ projector showed how consumer hardware can feed that ecosystem. Investigators found preinstalled firmware components, including com.hotack.silentsdk and com.hotack.writesn, generating suspicious DNS requests such as usmyip.kkoip.com and appearing designed to register the owner’s IP address for possible enrollment into a residential proxy network without consent. Researchers warned the issue may extend to other inexpensive Android projectors tied to Hotack, Huyukang, and Nonete, reinforcing concerns that cheap, poorly vetted smart devices are being used as covert infrastructure for proxy botnets and related criminal activity, including card fraud operations and DDoS abuse.

Jul 28
Cert Az

A $35 projector has turned into a source of hidden cyberthreats

Jul 27
The Hacker News

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Researchers reported that the Dysphoria IoT botnet, a lineage linked to JackSkid, changed its command-and-control design after a March law-enforcement disruption targeting JackSkid infrastructure. According to CNCERT and XLab, the operators replaced more traditional C2 dependencies with Ethereum Name Service (ENS) and Solana Name Service (SNS) records, allowing infected devices to resolve controller information through blockchain-based naming systems and making infrastructure takedowns more difficult. XLab said Dysphoria evolved rapidly from late March through June, adding ENS resolution, SNS resolution, a relay-only variant, and UPnP port mapping to help compromised devices traverse NAT environments. The botnet is reported to spread primarily through weak Telnet and SSH credentials, along with some known IoT remote-code-execution flaws, and it also uses infected devices as relay nodes to obscure backend controllers; however, the reported bot counts and attack scale have not been independently verified, and no operator or victim organizations were publicly identified.

Jul 27
Bleeping Computer

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Jul 25
Qianxin Xlab

僵尸网络新秀:Dysphoria 演进与深度技术分析

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.