KimWolf is an Android- and IoT-focused DDoS botnet and DDoS-for-hire platform, widely described as a variant of the Aisuru botnet. Reporting in the provided content states that it primarily targeted Android TV boxes, streaming devices, webcams, digital photo frames, and other Android-based or IoT systems, including devices with exposed Android Debug Bridge (ADB). Multiple sources in the content describe KimWolf as one of the largest and most damaging DDoS botnets observed in early 2026, with estimates ranging from more than 1 million to over 2 million compromised devices, roughly 12 million unique IP addresses seen weekly, more than 25,000 attack commands, and attacks peaking at approximately 30 to 31.4 Tbps. It was operated as a subscription-based cybercrime-as-a-service or DDoS-for-hire offering used by other criminals, and attacks included targets worldwide, including Department of Defense Information Network (DoDIN) IP space.
The content links KimWolf closely to abuse of residential proxy infrastructure, especially IPIDEA. Researchers reported that the botnet tunneled through IPIDEA proxy connections into the local networks behind proxy endpoints, infecting additional Android-based devices behind victim firewalls and probing internal networks. Several sources state that many infections stemmed from vulnerabilities in residential proxy networks, giving attackers access to devices on internal networks. The malware is also described as targeting off-brand Android TV hardware marketed under names such as TV BOX, SuperBox, XBOX, and SmartTV, with some reporting tying affected devices to broader Android supply-chain compromise patterns.
Capabilities explicitly mentioned in the content include DDoS attack functionality, proxy forwarding, reverse shell access, and file management. Additional reported technical characteristics include compilation with the Android NDK, use of DNS over TLS to conceal communications, elliptic-curve digital signatures to authenticate command-and-control instructions, simple stack XOR encryption for sensitive data, and later incorporation of EtherHiding via blockchain domains to resist takedowns. One source also notes tracked version naming patterns including "niggabox + v[number]" and references versions v4 and v5.
KimWolf has been associated with law-enforcement action by the United States, Canada, and Germany. The content states that authorities disrupted infrastructure tied to KimWolf in March 2026 alongside Aisuru, JackSkid, and Mossad, and later arrested and charged Ottawa resident Jacob Butler, also known as Dort, for allegedly developing or operating the botnet. Indicators and artifacts directly mentioned in the content include the account resi[.]to, Discord-linked administration records, and observation of about 2.7 million IP addresses interacting with one KimWolf C2 domain over three days. High-confidence victimology in the content centers on globally distributed Android and IoT devices and organizations impacted by large-scale volumetric DDoS attacks, including some suffering losses exceeding $1 million.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Another variant, KimWolf, targets Android systems, including mobile phones and Smart TVs.
"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"
"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Prime targets included Android TVs and streaming devices with exposed Android Debug Bridge (ADB) services.
It encrypts sensitive data with a simple Stack XOR... Recent versions even incorporate EtherHiding to resist takedowns via blockchain domains.
In March 2026, authorities in the United States, Germany, and Canada seized command-and-control systems linked to KimWolf and three related botnets identified as Aisuru, JackSkid, and Mossad.
It encrypts sensitive data with a simple Stack XOR, uses DNS over TLS to hide communication, and authenticates C2 commands with elliptic curve digital signatures.
В первом квартале аналитики Synthient нашли связь нашумевшего ботнета Kimwolf с прокси-сетью IPIDEA. Затем эта сеть была ликвидирована при участии GTIG.
A proxy inside a private network allows both inbound internet traffic and access to internal systems.
NetNut est identifié comme l’infrastructure commerciale reposant sur le botnet Popa ... transformés en nœuds de proxy résidentiels permanents ... Ces nœuds sont loués à des tiers ... Dissimulation d’origine d’acteurs malveillants ... T1090.002 — Proxy: External Proxy (Command and Control)
Kimwolf botnet has compromised more than 2 million Android devices, spreading primarily via residential proxy networks... Its primary function is traffic proxying, though it can execute massive DDoS attacks.
Kimwolf/Aisuru Tactic Technique ID Application C2 Web Service T1102.002 Ethereum ENS (pawsatyou[.]eth)
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
137 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet mentioned only in related-content links, with no operational details in the article body.
DDoS botnet referenced as part of the broader proxy ecosystem; described as having been built by tunneling through IPIDEA connections.
A DDoS botnet built by abusing residential proxy connections to reach into home networks and infect additional Android-based devices behind victims’ firewalls.
A botnet allegedly responsible for large-scale DDoS attacks; its development kits were reportedly used by the IPIDEA proxy network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.