Kimwolf is a large Android-focused botnet and cybercriminal operation that emerged in 2025 as an Android variant or splinter of Aisuru. It is associated with Mirai-style distributed denial-of-service activity and with monetization through residential proxy abuse and attack-for-rent services. The botnet has been reported at scales exceeding 1.8 to 2 million compromised devices globally, primarily affecting Android TV boxes, smart TVs, digital photo frames, tablets, and other low-cost Android-based or IoT devices, including devices shipped with insecure firmware, preinstalled malware, or Android debugging exposed by default. Kimwolf is notable for record-setting DDoS activity, including attacks reported at roughly 31.4 Tbps, and for its ability to compromise devices that are not directly exposed to the public internet by abusing residential proxy infrastructure to reach internal network addresses. Reporting also links the operation to large-scale scanning for exposed Android Debug Bridge services and to propagation through unofficial Android ecosystems and vulnerable consumer hardware. In addition to DDoS-for-hire operations, Kimwolf has been tied to proxy resale and broader cybercrime-as-a-service activity. The operation demonstrates resilient command-and-control tradecraft, including rapid infrastructure rotation and use of blockchain-based ENS naming for C2 continuity. It has also been associated with stealth and persistence on infected Android devices, remote command execution, and pivoting from compromised Android endpoints into local networks to infect additional systems. Law-enforcement actions in 2026 disrupted portions of the botnet’s command-and-control infrastructure alongside Aisuru, JackSkid, and Mossad, but the underlying infected-device population and business model were assessed as likely to persist. Aliases and closely linked names include KimWolf, kimwolf_botnet, kimwolf_operators, and Aisuru’s Android-focused variant. Public reporting also links operator personas such as “Dort” and “Snow” to the Kimwolf ecosystem. Available reporting characterizes Kimwolf as a cybercriminal rather than state-sponsored operation, with activity centered on DDoS, proxy monetization, and related illicit services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Major botnet allegedly responsible for large-scale DDoS attacks; reportedly used development kits from the IPIDEA proxy network.
Multinational botnet operation targeting Android TV devices for DDoS-for-hire and residential proxy resale, using Mirai-derived malware, SOCKS proxying, ENS-based resilient C2, and trojanized APKs plus ADB exploitation.
Botnet used for large-scale DDoS attacks; noted as particularly capable of infecting devices traditionally hidden behind firewalls and rented out as attack infrastructure.
Botnet operation used for DDoS attacks; the content says Kimwolf mainly infects Android-based streaming devices such as TV boxes, Smart TVs, Android tablets, and digital photo frames, and was responsible for about 25,000 DDoS attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.