Security researchers reported explosive growth of the Kimwolf botnet to 2+ million infected devices globally, with heavy concentrations including Vietnam, Brazil, India, Saudi Arabia, Russia, and the United States. Synthient assessed that roughly two-thirds of infections are insecure Android TV boxes, and described Kimwolf’s primary impact as large-scale abuse traffic (ad fraud, account takeover attempts, scraping) and high-capacity DDoS capable of disrupting major websites for extended periods. A key concern is Kimwolf’s propagation method: leveraging residential proxy networks to effectively tunnel “back” into home/SMB networks via proxy endpoints and then infect additional devices that users assume are protected behind NAT/firewalls and consumer routers.
KrebsOnSecurity further tied operational activity to the botnet controller, a threat actor using the handle “Dort,” who allegedly retaliated against a vulnerability discloser and the journalist with DDoS, doxing, email flooding, and an apparent SWATing incident. Open-source and commercial intelligence cited in the reporting linked “Dort” to historical aliases (e.g., CPacket, M1ce) and to accounts on cybercrime forums, and noted prior involvement in enabling abuse tooling (e.g., CAPTCHA-bypass code and temporary email services) and presence in communities associated with cybercrime groups (including references to LAPSUS$ chat activity).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Court documents and DOJ statements said the four Mirai-variant botnets collectively infected at least 3 million devices, issued hundreds of thousands of DDoS commands, and were used in attacks reaching roughly 30 to 31.4 Tbps, including extortion activity.
On March 20, 2026, the U.S. Department of Justice announced a court-authorized operation, coordinated with authorities in Canada and Germany, to disrupt command-and-control infrastructure for the Kimwolf, AISURU, JackSkid, and Mossad botnets.
On February 28, 2026, KrebsOnSecurity reported that the Kimwolf controller known as 'Dort' allegedly retaliated against the disclosure with DDoS attacks, doxing, email flooding, and an apparent swatting incident targeting Benjamin Brundage.
By late February 2026, researchers reported Kimwolf had expanded to more than 2 million infected devices globally, with major concentrations in Vietnam, Brazil, India, Saudi Arabia, Russia, and the United States.
Following the January 2026 disclosure, affected providers including IPIDEA said they blocked the vulnerable paths, added mitigations against DNS resolution to private ranges, and restricted risky ports; Brundage said the issue appeared patched and Kimwolf's propagation slowed.
On January 2, 2026, KrebsOnSecurity published research describing how the Kimwolf botnet was spreading by abusing weaknesses in residential proxy networks to access insecure IoT and Android devices on private home networks.
In December 2025, Synthient founder Benjamin Brundage disclosed to 11 residential proxy providers that their services could be abused to reach internal RFC1918 addresses and facilitate Kimwolf infections on devices behind home routers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcekrebsonsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.