Byteconnect SDK (also referred to as the Plainproxies Byteconnect SDK) is a proxy/bandwidth-monetization SDK observed by Synthient being installed in-the-wild in connection with the Kimwolf Android DDoS/proxy botnet ecosystem. Synthient reported that Kimwolf actors installed the Byteconnect SDK (sample hash: e465e625c1f85527e7082ff70dc479b5) as part of monetization via paid/covert app installs (earning referral fees). Upon connecting to the SDK, Synthient observed an influx of credential-stuffing activity originating from the associated proxy infrastructure, targeting IMAP servers and popular online websites. The content also describes Byteconnect SDK being used as a hidden tool to secretly install apps on victim devices without user knowledge. No additional technical IOCs (e.g., C2 domains, package names, persistence mechanisms) specific to Byteconnect SDK beyond the cited hash and observed behavior are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Byteconnect SDK is a hidden tool used by Kimwolf operators to secretly install apps on infected devices, generating referral fees without user knowledge.
Commercial bandwidth-monetization/proxy SDK observed being installed on compromised Android devices; uses relay servers and a C2/tasking flow to route proxy tasks through victim devices, and was observed facilitating credential-stuffing traffic against IMAP and popular websites.
Commercial bandwidth-monetization/proxyware SDK installed on compromised Android devices; connects to Byteconnect infrastructure to receive proxy tasks and was observed facilitating credential-stuffing traffic (e.g., against IMAP and popular websites).
Commercial proxy/bandwidth monetization SDK observed installed on compromised devices; uses relay servers and a C2/tasking flow to route proxy tasks through victim devices and was observed facilitating credential-stuffing traffic via the proxy channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.