Kimwolf is an Android-focused botnet associated with large-scale compromise of consumer devices and subsequent abuse of those devices as part of a residential proxy ecosystem. It has been reported at multi-million-device scale and is notable for using infected endpoints to expose victim network connectivity to third parties, creating both external abuse risk and internal network exposure.
The malware’s operational model aligns with proxyware-enabled botnets: compromised mobile devices are enrolled into a network that can relay traffic on behalf of remote users or operators. This allows malicious activity to be routed through legitimate residential or mobile IP space, helping adversaries evade reputation-based defenses and blend into normal consumer traffic. In enterprise environments, this creates legal, reputational, and incident-response complications because abuse may appear to originate from employee or guest devices connected to corporate networks.
Kimwolf has also been linked to local-network reconnaissance and probing behavior. Reporting indicates it can stalk or scan nearby networks, making it more than a passive proxy node. If a proxy-enabled implant permits access to internal address space, infected devices can provide a foothold for discovery or attacks against routers, IoT devices, and other systems reachable on the local network.
Observed infection vectors are consistent with the broader residential proxy and proxyware ecosystem, including consumer-facing Android applications that monetize installations by sharing bandwidth or IP access. Such distribution commonly overlaps with free VPN, streaming, utility, or other low-cost consumer app categories, although precise delivery chains for Kimwolf are not fully established in the available information.
Kimwolf primarily affects Android devices, but its impact extends beyond the handset itself to home and enterprise networks to which the device connects. Sectors with broad exposure to residential proxy activity include government, banking, healthcare, education, pharmaceuticals, and food and beverage, indicating that organizations with large mobile populations or unmanaged-device exposure may face elevated risk. Publicly available information does not currently attribute Kimwolf to a specific named threat actor with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Another concern is the potential for probing internal networks, as the Kimwolf Botnet did. An ethically designed residential proxy would block routing to internal IP addresses, but if the app allows for it, threat actors would be able to launch attacks on internal devices.
Residential proxies produce laundered (disguised) traffic—the destination believes it knows exactly who is connecting, but it is wrong. This is exactly what makes residential proxies valuable to attackers: They evade IP reputation systems that protect datacenter infrastructure They bypass fraud detection and verification controls They allow abuse traffic to blend into “normal” consumer noise
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet associated with residential proxy abuse that was observed inside enterprise customer networks and noted as having the potential to probe internal networks via compromised or proxy-enabled devices.
Android botnet reported to have infected approximately two million devices.
A named botnet reported as infecting approximately two million Android devices.
Kimwolf Botnet is a botnet malware that targets local networks for malicious activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.