Kimwolf is a cybercriminal botnet operation focused on compromising Android-based consumer and IoT devices, especially unofficial Android TV boxes, smart TVs, streaming devices, tablets, digital photo frames, and other poorly secured embedded systems. It is widely assessed as an Android-focused variant or splinter of the Aisuru botnet ecosystem that emerged in 2025 and rapidly grew to more than two million infected devices globally. Kimwolf is primarily associated with large-scale distributed denial-of-service operations and residential proxy monetization. The botnet has been linked to some of the largest publicly disclosed DDoS attacks observed, including attacks exceeding 30 Tbps, and has also been described as operating under a cybercrime-as-a-service model that rents attack capacity and proxy access to other criminals. Its operators have been characterized as technically capable and adaptive, with rapid infrastructure rotation and resilience against disruption. The botnet primarily targets devices with weak security controls, including systems shipped with Android debugging enabled by default, vulnerable firmware, preinstalled malicious components, or exposure through residential proxy ecosystems. Reported infection vectors include preinstalled malware in the supply chain, malicious or unofficial Android applications, exploitation of exposed ADB services, and abuse of residential proxy networks to reach devices on internal networks that would otherwise be shielded behind firewalls. Kimwolf has also been reported to pivot from compromised Android devices into local networks to infect additional systems. Operationally, Kimwolf combines Mirai-style botnet behavior with Android-specific tradecraft. Reported capabilities include scanning for exposed services, establishing persistent control over infected devices, using resilient command-and-control mechanisms including blockchain-based ENS naming, and leveraging proxy infrastructure for stealth, monetization, and follow-on access. The botnet has been associated with reverse-shell style remote control, covert proxying, bandwidth resale, and post-compromise abuse of residential IP space to disguise malicious traffic. Reporting also links Kimwolf to use of proxy monetization ecosystems associated with IPIDEA and related SDK-driven residential proxy services. Kimwolf has been tied to competition and overlap with other Android botnet and proxy ecosystems, including Aisuru, Bigpanzi, BadBox, and Vo1d, all of which target similar populations of vulnerable Android TV and embedded devices. The operators have been publicly linked to aliases including Dort and Snow, and some reporting has connected Kimwolf, Aisuru, and related botnet development activity to a multinational criminal grouping with ties to Canada and Germany. Law enforcement actions by the United States, Canada, and Germany in March 2026 disrupted command-and-control infrastructure associated with Kimwolf alongside Aisuru, JackSkid, and Mossad, but the underlying infected device population was not fully remediated. Kimwolf’s dominant motivation is financial gain through DDoS-for-hire services, proxy resale, and related criminal monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Major botnet allegedly responsible for large-scale DDoS attacks; reportedly used development kits from the IPIDEA proxy network.
Multinational botnet operation targeting Android TV devices for DDoS-for-hire and residential proxy resale, using Mirai-derived malware, SOCKS proxying, ENS-based resilient C2, and trojanized APKs plus ADB exploitation.
Botnet used for large-scale DDoS attacks; noted as particularly capable of infecting devices traditionally hidden behind firewalls and rented out as attack infrastructure.
Botnet operation used for DDoS attacks; the content says Kimwolf mainly infects Android-based streaming devices such as TV boxes, Smart TVs, Android tablets, and digital photo frames, and was responsible for about 25,000 DDoS attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.