Lumen Technologies’ Black Lotus Labs reported disrupting the AISURU/Kimwolf botnet ecosystem by null-routing/dropping traffic to more than 550 command-and-control (C2) nodes and IPs linked to the botnets’ backend infrastructure since early October 2025. The operation targeted two closely related, financially motivated botnets—AISURU and its Android-focused counterpart Kimwolf—that have become major sources of DDoS activity and residential proxy abuse, with Kimwolf drawing attention after a related domain briefly surged to the top of Cloudflare’s global domain rankings before being removed from the list.
Researchers assessed Kimwolf as having compromised over 2 million devices, largely unofficial/unsanctioned Android TV streaming boxes, leveraging exposed Android Debug Bridge (ADB) services and tunneling through residential proxy networks to expand access and maintain control. Reporting also described Kimwolf’s use of proxy monetization (including attempts to offload proxy bandwidth for upfront cash) and noted that the operators reacted to disruption efforts with provocative messaging embedded in DDoS payloads; observed DDoS patterns were often short bursts (1–2 minutes) but sometimes extended for hours, with gaming services (e.g., Minecraft) cited as a common target category.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On January 14, 2026, public reporting disclosed that Black Lotus Labs had null-routed traffic to more than 550 command-and-control nodes tied to the AISURU and Kimwolf botnets, detailing their DDoS-for-hire and residential proxy abuse operations.
During the four-month disruption effort, Lumen shared findings on infrastructure linked to Canadian IP addresses with law enforcement as operators repeatedly rebuilt command-and-control systems within hours.
By late 2025, researchers assessed that Kimwolf had likely exceeded 1.8 million infections and compromised more than 2 million unofficial Android TV devices overall, making it one of the largest observed Android botnets.
In late October 2025, Kimwolf drew major attention after briefly becoming the top-ranked domain in Cloudflare's global rankings, reflecting the botnet's sudden scale and visibility.
By mid-October 2025, Lumen estimated Kimwolf had grown to roughly 800,000 infected devices within weeks of emerging, driven by exploitation of vulnerable residential proxy services.
Since October 1, 2025, Infoblox observed that nearly 25% of its cloud customers queried a Kimwolf domain, which researchers said indicated broad scanning activity even if not confirmed compromise.
In early October 2025, researchers observed infrastructure changes consistent with Kimwolf's emergence. The botnet rapidly expanded by abusing residential proxy services and exposed ADB services to compromise unofficial Android TV devices.
Beginning in early October 2025, Lumen Technologies' Black Lotus Labs started blocking and null-routing command-and-control infrastructure associated with Kimwolf and AISURU, eventually targeting more than 550 nodes.
Lumen's Black Lotus Labs observed a surge in bot traffic to AISURU command-and-control infrastructure in September 2025, indicating growing activity from the botnet before Kimwolf's emergence.
In September 2025, Cloudflare reported that the AISURU botnet generated a 29.7 Tbps distributed denial-of-service attack lasting 69 seconds, highlighting the scale of the broader botnet ecosystem tied to Kimwolf.
Researchers said Kimwolf splintered from the Aisuru botnet in August 2025, marking the emergence of a distinct Android-focused botnet linked to the same ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecyberscoop.com
Open sourcethehackernews.com
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.