Last seven days
- First activity
- Sep 14, 2026
- Last activity
- Sep 14, 2026
- Feed role
- C2
- Host form
- 14 IP / 0 hostnames
Kimwolf is an Android-focused IoT botnet, also tracked in connection with the AISURU/Aisuru lineage, that primarily compromises Android TV boxes and set-top devices.
Profile source: Mallory opens in a new tabKimwolf
Kimwolf is an Android-focused IoT botnet, also tracked in connection with the AISURU/Aisuru lineage, that primarily compromises Android TV boxes and set-top devices. Active since at least 2024 and focused on Android targets from 2025, it abuses exposed, unauthenticated Android Debug Bridge services, commonly reached by tunneling through residential proxy networks into victim local networks. Supporting Android packages have masqueraded as system services and deployed embedded ELF payloads.
Kimwolf is principally used for distributed denial-of-service attacks and traffic relaying. Version 7 introduced browser-emulating HTTP/2 floods that reproduce Chrome-like request behavior and headers, alongside an ARM-optimized UDP flood and additional layer 3–7 attack methods. Its command-and-control architecture uses Ethereum Name Service resolution through public blockchain RPC services, a local proxy layer, and a Tor hidden-service fallback to improve resilience against infrastructure disruption. Version 7 removed scanning, exploitation, and brute-force functions from the main bot binary, consistent with separation of initial-access operations from DDoS execution and proxy-relay functions.
Observed activity also includes local scanning for Android Debug Bridge services and delivery of proxy payloads that turn compromised devices into TCP and UDP relays. This enables residential-proxy expansion and may facilitate reconnaissance or access to systems on victim local networks. Kimwolf was among botnets affected by multinational law-enforcement infrastructure disruption in March 2026. Public reporting links its infrastructure, payload characteristics, and operational behavior with Aisuru, although definitive operator attribution remains unconfirmed.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Menace émergente : Kimwolf/Dort # L’acteur individuel Dort a introduit une nouvelle menace en exploitant les proxies résidentiels eux-mêmes comme vecteur pour créer des botnets DDoS , atteignant un pic de ~400 000 IPs exploitées en un seul jour (février-mars 2026).
Another variant, KimWolf, targets Android systems, including mobile phones and Smart TVs.
"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"
Exploited software
MITRE ATT&CK
Reporting
A March multinational operation involving the United States, Canada, and Germany disrupted infrastructure supporting the Aisiru and Kimwolf botnets, contributing to a fall in the largest observed botnet from 13.5 million devices in Q1 2026 to 2.09 million in Q2. Link11 also reported a 42% decline in DDoS attacks in Europe during the first half of 2026, partly attributing the reduction to law-enforcement actions including Operation Eastwood and the shutdown of four IoT botnets. Attackers are compensating with more powerful and resilient campaigns: Link11 recorded peaks of 2.3 Tbit/s and 322 million packets per second, with 705 TB of cumulative malicious traffic, driven by super-botnets and hijacked cloud servers. Operators are increasingly dispersing traffic sources and adopting decentralized command infrastructure; the Aeternum and Void botnets use Polygon and Ethereum smart contracts for C2 distribution. DDoS surges are also being used to conceal SQL-injection and XSS probing, requiring defenses that combine continuous traffic inspection, behavioral detection, adaptive filtering, and application-layer monitoring.
U.S., Bulgarian, Hungarian, and Romanian authorities, supported by CrowdStrike and the Shadowserver Foundation, disrupted the long-running Sality peer-to-peer botnet by seizing payload-hosting domains, dismantling control infrastructure, and sinkholing its super-peer network. The operation exploited Sality's unauthenticated peer-list protocol to redirect infected hosts away from operator-controlled infrastructure, cutting off delivery of new malware payloads and removing the botnet from the operators' control. Active since at least 2003, Sality infected more than 15,000 devices and spread by infecting Windows executables. CrowdStrike attributes the operation to SALTY SPIDER, a criminal group likely based in Russia's Republic of Bashkortostan; its infrastructure supported credential theft, spam, proxying, network exploitation, DDoS activity, and EggJagger cryptocurrency clipboard hijacking. Organizations should investigate UDP communications with 188.166.101[.]148, an indicator of Sality infection, because sinkholing prevents new payload delivery but does not remove malware from already compromised systems.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.