The Kimwolf botnet has rapidly infected over 1.8 million Android-based devices worldwide, with security researchers warning that the true number may exceed 2 million. The malware primarily targets Android TV boxes, digital photo frames, and other IoT devices, many of which are distributed through major online retailers and often ship with weak security controls or pre-installed malicious software. Kimwolf leverages advanced techniques such as DNS-over-TLS, blockchain-based command and control via Ethereum Name Service (ENS), and residential proxy networks to evade detection and takedown efforts. The botnet enables attackers to launch high-volume DDoS attacks, monetize proxy bandwidth, and conduct lateral movement within local networks, posing a significant threat to both enterprise and consumer environments.
Security experts have identified that two-thirds of Kimwolf infections are Android TV boxes lacking basic authentication, making them especially vulnerable. The operators behind Kimwolf, previously linked to the Aisuru botnet, are known for their technical sophistication and rapid adaptation to takedown attempts. Their monetization strategies include ad fraud, DDoS-for-hire services, and the resale of residential proxy bandwidth. The malware often spreads through bundled mobile apps and games, exploiting the global supply chain of low-cost Android devices. Organizations and individuals are urged to identify, isolate, and remediate infected devices to prevent further exploitation and participation in criminal infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Breakglass Intelligence reported that claims tying the Android TV botnet conflict to North Korea's Kimsuky were incorrect, assessing instead that Kimwolf/Aisuru is a separate cybercrime botnet competing with Bigpanzi. The report said the activity reflects criminal competition over vulnerable Android TV devices rather than a state-sponsored campaign.
Network operators on the NANOG mailing list reported that Android-based SuperBox IPTV set-top boxes infected with Kimwolf were causing customer IP addresses to be blocklisted and service disruptions. They noted that replacing customer routers only temporarily changed the blocked IP while the infected device remained active.
Following researcher notification, IPIDEA publicly acknowledged the internal-access issue and said it had blocked the relevant paths and ports, while Oxylabs said it had implemented mitigations and found no evidence of exploitation on its network. These responses highlighted broader supply-chain risk in residential proxy services.
By early January 2026, Synthient and XLab reported that Kimwolf had infected roughly 1.8 to more than 2 million devices globally. They detailed how the botnet abused residential proxy networks and exposed ADB to compromise Android TV boxes, photo frames, and similar devices for proxy resale, fraud, credential attacks, and DDoS.
IPIDEA said it addressed a legacy testing/debug module in December 2025 by blocking affected access paths, tightening DNS-to-private-range controls, and restricting high-risk ports. The changes were made after researchers identified that the proxy service could be abused to reach internal LAN resources.
Researchers later attributed Kimwolf's sharp growth in late 2025 to abuse of residential proxy networks, especially IPIDEA-rented proxy IPs, combined with insecure gray-market Android devices. During this period, the botnet rebuilt quickly even after disruption attempts.
XLab observed a Kimwolf command-and-control domain rapidly rise in popularity in late October 2025, providing early telemetry that the botnet was expanding quickly. This activity helped indicate a large and growing infection base.
Synthient assessed that the Kimwolf botnet had been active since at least August 2025, primarily compromising Android TV boxes, streaming devices, digital photo frames, and other IoT hardware. The malware spread through exposed or unauthenticated ADB services, unofficial apps, and in some cases pre-infected devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourcekyberturvallisuuskeskus.fi
Open sourceseclists.org
Open sourceseclists.org
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcerescana.com
Open sourcekrebsonsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.