The Kimwolf “Internet of Things” botnet has been linked to major disruption of the anonymity network I2P (Invisible Internet Project) after botnet operators began using I2P to help evade takedown efforts against their command-and-control (C2) servers. I2P users reported that tens of thousands of new “routers” suddenly flooded the network, many unable to pass traffic, overwhelming I2P to the point that legitimate users could not connect; developers and users described extreme connection counts and a sharp drop in successful connections consistent with a large-scale availability attack.
Separately, a major U.S. ISP reported actively sinkholing/blocking traffic to hundreds of botnet C2 servers associated with Kimwolf (and the related Aisuru botnet), citing more than 550 identified C2 endpoints over several months. Reporting attributes Kimwolf’s growth to at least ~2 million infected devices, with operators leveraging compromised Android TV set-top boxes and scanning for exposed Android Debug Bridge (ADB) services to expand the botnet and monetize access via residential proxy infrastructure that makes malicious traffic appear to originate from consumer networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Over a four-month period ending by February 2026, a major U.S. internet service provider said it blocked incoming traffic to more than 550 command-and-control servers associated with the Kimwolf and Aisuru botnets. The action reflected sustained mitigation against rapidly expanding botnet infrastructure.
By February 2026, observers reported that Kimwolf's bot population had recently fallen by more than 600,000 systems. The decline was attributed to operator mistakes and internal friction among the botnet's developers or operators.
During the weeklong disruption in February 2026, I2P leadership said the network was operating at about half capacity and that a new software release was being deployed to improve stability. The issue was consistent with a Sybil-style overload caused by the influx of Kimwolf-linked nodes.
Beginning on Feb. 3, 2026, tens of thousands of new routers flooded the I2P anonymity network, disrupting legitimate connectivity for about a week. Researchers linked the event to Kimwolf operators attempting to use I2P as a fallback command-and-control channel for roughly 700,000 infected bots.
After the late-October to early-November scanning activity, IP addresses associated with 2 million infected Android devices were made public and then leased by threat actors. The devices had been compromised largely through exposed Android Debug Bridge services and abuse of local DNS settings.
Between Oct. 20 and Nov. 6, 2025, Kimwolf command-and-control infrastructure scanned for PYPROXY and other vulnerable connections. Researchers said this activity preceded the public exposure and leasing of IP addresses tied to 2 million infected Android devices.
Black Lotus Labs observed sharp growth in Kimwolf during October 2025, with the botnet reaching about 800,000 infected devices by mid-month. Many of those bots were reportedly being marketed through a single residential proxy service.
Infoblox reported that about a quarter of its cloud customers queried a known Kimwolf domain starting on Oct. 1, 2025, indicating broad exposure to infrastructure tied to the botnet's residential proxy ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.