Dort is an individual cybercriminal associated with the Aisuru/Kimwolf botnet ecosystem and with the use of compromised consumer devices and malicious residential proxy infrastructure for distributed denial-of-service operations. Reporting links Dort to control of the Aisuru/Kimwolf botnet alongside at least one other operator, and identifies Dort as an emerging actor who adapted residential proxy networks themselves into a DDoS botnet vector. The actor is tied to Kimwolf and its predecessor Aisuru, botnets associated with mass compromise of unofficial Android TV streaming boxes and related consumer devices. These botnets have been used both to relay abusive traffic for proxy services and to conduct large-scale DDoS attacks. Dort has been specifically associated with exploiting residential proxy ecosystems as an attack substrate, reaching roughly 400,000 exploited IPs in a single day during peak activity in early 2026. Operationally, the activity linked to Dort overlaps with botnet-enabled proxy abuse, large-scale traffic relaying, and destructive or disruptive network attacks. The broader Aisuru/Kimwolf ecosystem has also been linked to resilient command-and-control approaches, including use of Ethereum Name Service records for control-server discovery and operator messaging, as well as retaliatory harassment and DDoS activity against researchers and organizations investigating the botnet. Known associated names in this ecosystem include Kimwolf, Aisuru, and the alleged co-operator Snow.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Individual cybercriminal actor using malicious residential proxies themselves as a vector to build DDoS botnets at significant scale.
Named botnet operator/botmaster associated with controlling and operating the Aisuru/Kimwolf botnet infrastructure, including proxy monetization and DDoS capability.
Named botnet operator/botmaster associated with the Aisuru/Kimwolf botnet ecosystem, tied to residential proxy monetization and DDoS activity; linked to resi[.]to Discord operations and subsequent migration to Telegram after exposure.
Named botmaster/operator associated with controlling the Aisuru/Kimwolf botnet infrastructure used for DDoS and residential proxy abuse; linked to the resi[.]to Discord server administration and subsequent operational security reactions (chat log deletion, migration to Telegram, doxing).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.