Skip to main content
Mallory
1 malware family

Snow

Also known assnow

Snow is identified in reporting as a nickname/handle of an alleged botmaster involved in operating the Aisuru/Kimwolf botnet ecosystem. The Kimwolf botnet is described as mass-compromising unofficial/unsanctioned Android TV streaming boxes at scale (reported as >2 million infected devices) and then coercing infected devices to conduct DDoS attacks and relay abusive/malicious traffic as “residential proxy” exit nodes. XLab reported “definitive evidence” linking Kimwolf to the earlier Aisuru botnet via shared infrastructure and code evolution, including observation of both strains being distributed from the same IP (93.95.112[.]59). The operation is also described as leveraging proxy-related tooling and services (including installation of ByteConnect/Plainproxies SDK and involvement of Maskify in selling access to Kimwolf proxies), with observed downstream activity including credential-stuffing traffic when connecting to ByteConnect’s SDK. After public reporting, the operators allegedly retaliated by deleting Discord history, doxing a researcher (Benjamin Brundage of Synthient), and launching DDoS attacks against Synthient. The operators reportedly adopted Ethereum Name Service (ENS) text records as a resilient C2 discovery mechanism by updating ENS records with new control-server IPs and also used ENS to post taunting/doxing messages. Another alleged controller named alongside Snow is “Dort” (suggested to be associated with a Discord username “D”); a source (“Forky”) claimed Dort (a resident of Canada) and Snow were among those controlling Aisuru/Kimwolf.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics8 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1584
Compromise Infrastructure
T1584.005
Botnet
TA0009
Collection
2 techniques
T1074
Data Staged
T1213
Data from Information Repositories
TA0011
Command and Control
1 technique
T1090
Proxy
T1090.003
Multi-hop Proxy
TA0040
Impact
1 technique
T1498
Network Denial of Service
T1498.001
Direct Network Flood
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.