The Kimwolf botnet has infected approximately 1.8 million Android-based devices worldwide, including smart TVs, set-top boxes, and tablets, making it one of the largest Android botnets identified to date. Security researchers from Xlab Qianxin and other organizations discovered that Kimwolf leverages advanced evasion techniques such as DNS over TLS and elliptic-curve digital signatures to bypass detection and secure command verification. The malware is distributed globally, with the highest infection rates in Brazil, India, and the United States, and is capable of launching destructive cyberattacks at scale due to its robust network infrastructure.
Kimwolf is compiled using the Android NDK and provides attackers with a range of capabilities, including DDoS attacks, proxy forwarding, reverse shell access, and file management. The botnet has issued over 1.7 billion DDoS commands in a three-day period and has demonstrated resilience by shifting to Ethereum Name Service (ENS) for its command-and-control infrastructure after repeated domain takedowns. The infection mechanism involves an APK that extracts a native binary payload, ensuring persistence and single-instance execution on each device. The exact propagation method remains unclear, but the botnet's rapid evolution and global reach pose a significant threat to Android device security.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
In mid-December 2025, QiAnXin XLab publicly disclosed Kimwolf as a major Android botnet with DDoS, proxy forwarding, reverse shell, and file management capabilities. The report also detailed its stealth features, including DNS over TLS, ECDSA-authenticated commands, and encrypted multi-stage C2 communications.
Following additional apparent command-and-control takedowns, researchers observed a decline in Kimwolf's daily active node count. Despite this, the botnet's infrastructure showed resilience through fallback mechanisms including ENS-based EtherHiding for C2 retrieval.
After the C2 takeover, XLab observed millions of infected IP addresses and recorded a peak of roughly 1.83 million active bot nodes. Infections were seen across 222 countries and regions, with Brazil, India, and the United States among the most affected.
On December 1, researchers seized control of a Kimwolf command-and-control domain to observe the botnet's activity. This provided direct visibility into the scale and behavior of infected devices communicating with the infrastructure.
A Kimwolf command-and-control domain rapidly rose in popularity and briefly ranked first in Cloudflare's top 100 domains, reportedly surpassing Google within a week. The spike coincided with the botnet's large-scale DDoS activity and highlighted the scale of its infrastructure.
During a three-day period, Kimwolf was observed sending about 1.7 billion DDoS attack commands, demonstrating large-scale attack activity. Researchers said the botnet supported multiple DDoS methods and assessed its potential attack capacity at nearly 30 Tbps.
Researchers at QiAnXin XLab identified a new Android botnet dubbed Kimwolf affecting smart TVs, set-top boxes, tablets, and especially residential TV boxes. The botnet was reported as discovered in October 2025 and was later linked by researchers to the AISURU botnet family through shared code and artifacts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.