Kimwolf is an Android-focused IoT botnet, also tracked in connection with the AISURU/Aisuru lineage, that primarily compromises Android TV boxes and set-top devices. Active since at least 2024 and focused on Android targets from 2025, it abuses exposed, unauthenticated Android Debug Bridge services, commonly reached by tunneling through residential proxy networks into victim local networks. Supporting Android packages have masqueraded as system services and deployed embedded ELF payloads.
Kimwolf is principally used for distributed denial-of-service attacks and traffic relaying. Version 7 introduced browser-emulating HTTP/2 floods that reproduce Chrome-like request behavior and headers, alongside an ARM-optimized UDP flood and additional layer 3–7 attack methods. Its command-and-control architecture uses Ethereum Name Service resolution through public blockchain RPC services, a local proxy layer, and a Tor hidden-service fallback to improve resilience against infrastructure disruption. Version 7 removed scanning, exploitation, and brute-force functions from the main bot binary, consistent with separation of initial-access operations from DDoS execution and proxy-relay functions.
Observed activity also includes local scanning for Android Debug Bridge services and delivery of proxy payloads that turn compromised devices into TCP and UDP relays. This enables residential-proxy expansion and may facilitate reconnaissance or access to systems on victim local networks. Kimwolf was among botnets affected by multinational law-enforcement infrastructure disruption in March 2026. Public reporting links its infrastructure, payload characteristics, and operational behavior with Aisuru, although definitive operator attribution remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
„Најраниот пронајден примерок, кој ја таргетира x86 архитектурата со експлоатација на Dirty COW , укажува дека оваа фамилија еволуирала од традиционална Linux експлоатација кон актуелниот Android модел на ширење базиран на ADB“ | Истражувачи за сајбер-безбедност открија нова верзија на Android и Internet of Things (IoT) ботнетот Kimwolf/AISURU, која носи значителни подобрувања за зголемување на оперативната отпорност и за изведување дистрибуирани напади за одбивање на услугата (DDoS).
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Menace émergente : Kimwolf/Dort # L’acteur individuel Dort a introduit une nouvelle menace en exploitant les proxies résidentiels eux-mêmes comme vecteur pour créer des botnets DDoS , atteignant un pic de ~400 000 IPs exploitées en un seul jour (février-mars 2026).
Another variant, KimWolf, targets Android systems, including mobile phones and Smart TVs.
"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code.
“Beyond the C2 Takedown ... disrupting a botnet’s command-and-control infrastructure was a major step.”
“The primary path for resolution is ENS over Ethereum JSON-RPC. It picks a random public RPC node ... opens TLS to it on port 443, and issues Ethereum eth_call requests.”
“The bot first resolves its C2 from a DNS TXT dead-drop” and “dead drop domains ... update information in their TXT records with base64 and XOR encoded information to give the real backend IPs back to the bot.”
“The file dropped is a dedicated proxy bot that turns the infected device into a raw TCP/UDP relay for the operators.”
Ботнетот исто така има за цел да ја направи својата инфраструктура за командување и контрола (C2) поотпорна на обиди за нејзино отстранување, преку повеќеслоен механизам кој користи Ethereum Name Service (ENS) за добивање на C2-адресата, однапред вграден Tor .onion скриен сервис и локален прокси за рутирање меѓу clearnet и Tor.
“The highest measured bandwidth attack reached 2.3 Tbit/s” and “Attackers are steering their botnets with greater precision and control, generating more traffic in less time.”
“The highest measured bandwidth attack reached 2.3 Tbit/s” and “attackers used a traffic spike against two domains as cover.”
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
154 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kimwolf apparaît uniquement dans la liste « Malware / Outils ».
A super-botnet described as Aisuru's successor and as contributing to increasingly intense DDoS activity.
A botnet whose infrastructure was disrupted during a coordinated March 2026 law-enforcement operation.
Botnet whose infrastructure was disrupted during a coordinated March 2026 law-enforcement operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.