Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Jul 31, 2026
- Feed role
- C2
- Host form
- 10 IP / 0 hostnames
KimWolf is a large Android- and IoT-focused DDoS botnet operated as a cybercrime-as-a-service platform.
Profile source: Mallory opens in a new tabKimwolf
KimWolf is a large Android- and IoT-focused DDoS botnet operated as a cybercrime-as-a-service platform. It has been described as a variant of AISURU and has been linked to the online persona Dort, with law-enforcement actions in 2026 targeting both its infrastructure and its alleged operator. The botnet has been associated with very large volumetric attacks, including record-scale multi-terabit DDoS activity, and with more than 25,000 attack commands issued against targets worldwide, including systems associated with the U.S. Department of Defense Information Network.
KimWolf primarily compromises Android-based consumer and embedded devices, especially Android TV boxes, streaming devices, webcams, digital photo frames, and other internet-connected equipment. Reporting also ties its growth to abuse of residential proxy networks, where operators tunneled through proxy endpoints into local networks and infected additional Android devices behind victim firewalls. Some research further links KimWolf infections to exposed Android Debug Bridge services and to supply-chain style exposure involving low-cost Android TV hardware. Infected devices have been observed at very large scale, with public estimates ranging from more than one million to nearly two million compromised systems.
The malware’s functionality centers on distributed denial-of-service operations, but reported capabilities also include proxy forwarding, reverse-shell style remote access, and file-management features. Researchers have additionally documented efforts to harden its command-and-control resilience, including use of DNS over TLS, cryptographic authentication of commands, and blockchain-based naming mechanisms such as ENS-related infrastructure in some variants or related operations. KimWolf has been characterized as highly adaptable and resilient, with ties to the broader ecosystem of malicious residential proxy and IoT botnet activity.
KimWolf has been associated with attacks against enterprises, public-sector networks, and critical internet-facing infrastructure. It is part of a broader cluster of botnets disrupted alongside AISURU, JackSkid, and Mossad in multinational operations during 2026. The botnet is notable both for its scale and for its use of compromised consumer devices and residential-network access as a foundation for high-impact DDoS-for-hire services.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Menace émergente : Kimwolf/Dort # L’acteur individuel Dort a introduit une nouvelle menace en exploitant les proxies résidentiels eux-mêmes comme vecteur pour créer des botnets DDoS , atteignant un pic de ~400 000 IPs exploitées en un seul jour (février-mars 2026).
Another variant, KimWolf, targets Android systems, including mobile phones and Smart TVs.
"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"
MITRE ATT&CK
Reporting
Black Lotus Labs reported a sprawling malicious residential proxy ecosystem built from compromised IoT and SOHO routers, Android devices, and Android TV boxes, tracking nearly 20 million distinct IPs per day across 30+ botnet clusters. The research identified major services and botnets including IPIDEA, Jaguar, Kookeey, NetNut/Popa, G3Proxy, NSOCKS/Ngioweb, and ASOCKS/Nexusnet, and said many operators both maintain their own botnets and resell access to other infected devices. Lumen said more than 20 of the clusters regularly exceed 100,000 daily victims, with roughly half of the tracked malicious proxy botnets operated by Chinese actors and many services excluding mainland China from their proxy pools. Separate analysis of the low-cost Android-based Magcubic HY300 Pro+ projector showed how consumer hardware can feed that ecosystem. Investigators found preinstalled firmware components, including com.hotack.silentsdk and com.hotack.writesn, generating suspicious DNS requests such as usmyip.kkoip.com and appearing designed to register the owner’s IP address for possible enrollment into a residential proxy network without consent. Researchers warned the issue may extend to other inexpensive Android projectors tied to Hotack, Huyukang, and Nonete, reinforcing concerns that cheap, poorly vetted smart devices are being used as covert infrastructure for proxy botnets and related criminal activity, including card fraud operations and DDoS abuse.
Researchers reported that the Dysphoria IoT botnet, a lineage linked to JackSkid, changed its command-and-control design after a March law-enforcement disruption targeting JackSkid infrastructure. According to CNCERT and XLab, the operators replaced more traditional C2 dependencies with Ethereum Name Service (ENS) and Solana Name Service (SNS) records, allowing infected devices to resolve controller information through blockchain-based naming systems and making infrastructure takedowns more difficult. XLab said Dysphoria evolved rapidly from late March through June, adding ENS resolution, SNS resolution, a relay-only variant, and UPnP port mapping to help compromised devices traverse NAT environments. The botnet is reported to spread primarily through weak Telnet and SSH credentials, along with some known IoT remote-code-execution flaws, and it also uses infected devices as relay nodes to obscure backend controllers; however, the reported bot counts and attack scale have not been independently verified, and no operator or victim organizations were publicly identified.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.