Kimwolf is a cybercriminal botnet operation and Android-focused variant/splinter of Aisuru that emerged in 2025. It is widely described as one of the largest Android botnets, with reporting that it infected more than 2 million devices globally and operated across 222 countries/regions. Known aliases in the provided content include kimwolf, kimwolf_operators, and references tying it closely to Aisuru; some reporting describes Kimwolf as having splintered from Aisuru in August 2025, while other reporting states Kimwolf and Aisuru were likely operated by the same group. The operation is described as multinational, not a nation-state actor. Kimwolf primarily targets Android-based streaming devices and other weakly secured IoT/consumer devices, including Android TV boxes, Smart TVs, tablets, digital photo frames, and unofficial or no-name IPTV/streaming boxes. The content states many targeted devices shipped with Android debugging enabled by default, exploitable firmware, or were pre-infected before sale. Kimwolf also abused residential proxy networks to reach internal network addresses and scan for exposed ADB services, with observed targeting of ports 5555, 5858, 12108, and 3222. Reporting states the operators used compromised Android TV devices to pivot into local networks and infect additional devices, and that Kimwolf could infect devices traditionally hidden behind firewalls. The botnet’s main uses were large-scale distributed denial-of-service attacks and proxy/residential bandwidth monetization. Multiple sources state the operators rented access as a cybercrime-as-a-service offering for DDoS attacks and proxy services. Kimwolf was linked to record-setting DDoS activity, including attacks reported at 29.7 Tbps, 30 Tbps, and a 31.4 Tbps attack in late 2025/early 2026; one report attributes a December 2025 Cloudflare attack reaching 31.4 Tbps and 205 million requests per second to Kimwolf likely with assistance from Aisuru. The U.S. Department of Justice stated KimWolf issued about 25,000 attack commands, and coordinated law enforcement action in March 2026 disrupted infrastructure associated with KimWolf, Aisuru, JackSkid, and Mossad after the four botnets had compromised more than 3 million devices. The content also describes Kimwolf as heavily focused on proxying traffic and resale of compromised bandwidth. One report states 96.5% of bot commands were proxy-related. Google reported that IPIDEA infrastructure and SDKs were used by Kimwolf, and other reporting links Kimwolf’s monetization chain to Resi Rack LLC, IPIDEA, and the ByteConnect SDK. The botnet is also described as being used for ad fraud, account takeovers, web scraping, and residential-proxy-style cybercrime. Kimwolf is described as technically advanced and resilient. Reported command-and-control methods include resilient C2 via the ENS domain pawsatyou[.]eth and prior use of 14emeliaterracewestroxburyma02132[.]su. Additional reporting states the malware used DNS-over-TLS and blockchain-based ENS domains for C2, and rapidly shifted infrastructure after disruption. Downloader IPs in the 93.95.112.50-59 range associated with Resi Rack LLC are identified in the content. The malware is described as capable of reverse shells/remote control, multiple DDoS attack types, and manipulation of local router DNS settings. Named operators and personas mentioned in the content include “Dort” and “Snow”; reporting also links “Snow” or “Lucy” to development of KimWolf, Aisuru, and Mossad, and ties KimWolf administrators to British Columbia, Quebec, and Hanover. One article says a 22-year-old Canadian was believed to be the Kimwolf operator using the alias “Dort.” The content also notes that Kimwolf operators hacked a rival Badbox 2.0 backend and posted screenshots of the takeover. Overall, the provided content consistently characterizes Kimwolf as a large, technically sophisticated cybercriminal Android/IoT botnet ecosystem tied to Aisuru, focused on DDoS-for-hire and residential proxy monetization, and notable for exploiting insecure Android TV and related consumer devices at very large scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Major botnet allegedly responsible for large-scale DDoS attacks; reportedly used development kits from the IPIDEA proxy network.
Multinational botnet operation targeting Android TV devices for DDoS-for-hire and residential proxy resale, using Mirai-derived malware, SOCKS proxying, ENS-based resilient C2, and trojanized APKs plus ADB exploitation.
Botnet used for large-scale DDoS attacks; noted as particularly capable of infecting devices traditionally hidden behind firewalls and rented out as attack infrastructure.
Botnet operation used for DDoS attacks; the content says Kimwolf mainly infects Android-based streaming devices such as TV boxes, Smart TVs, Android tablets, and digital photo frames, and was responsible for about 25,000 DDoS attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.