Kimwolf is an Android-focused botnet associated with the Aisuru malware lineage and operators. Active in 2025, it primarily compromises non-certified Android TV boxes and set-top devices in residential networks, with infections also affecting smart TVs and tablets. Its infected population has been estimated at more than 1.8 million devices worldwide. Operators abuse residential proxy networks to reach exposed, unauthenticated Android Debug Bridge services on internal devices, enabling payload installation behind home firewalls. Observed operations include local-network scanning and deployment of additional Android proxy payloads.
Compiled using the Android Native Development Kit, Kimwolf supports distributed denial-of-service attacks, TCP and UDP proxy forwarding, reverse shells, remote command execution, and file reading and writing. Proxy-service commands dominated early observed activity, demonstrating its substantial role in residential traffic relaying alongside DDoS operations. Android delivery packages can launch embedded native payloads at boot and attempt execution with existing root privileges. The malware disguises itself as Android system processes and conceals infrastructure information through string obfuscation, encrypted communications, DNS over TLS, and encoded command-and-control addresses. It also authenticates command infrastructure using elliptic-curve signature verification.
Kimwolf v7, identified in February 2026, adds HTTP/2 floods that imitate Chrome browser fingerprints and header behavior, alongside ARM-optimized UDP flooding and other network- and application-layer attack methods. Its main binary removes built-in scanning, exploitation, and password-guessing modules, concentrating on attack execution and proxy relaying. Command infrastructure uses Ethereum Name Service records, public Ethereum RPC services, a local proxy component, and a Tor hidden-service fallback to improve resilience against disruption. An international operation involving authorities in the United States, Canada, and Germany disrupted Kimwolf command-and-control infrastructure in March 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
„Најраниот пронајден примерок, кој ја таргетира x86 архитектурата со експлоатација на Dirty COW , укажува дека оваа фамилија еволуирала од традиционална Linux експлоатација кон актуелниот Android модел на ширење базиран на ADB“ | Истражувачи за сајбер-безбедност открија нова верзија на Android и Internet of Things (IoT) ботнетот Kimwolf/AISURU, која носи значителни подобрувања за зголемување на оперативната отпорност и за изведување дистрибуирани напади за одбивање на услугата (DDoS).
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Kimwolf is a botnet compiled using the NDK. In addition to typical DDoS attack capabilities, it integrates proxy forwarding, reverse shell, and file management functions.”
Menace émergente : Kimwolf/Dort # L’acteur individuel Dort a introduit une nouvelle menace en exploitant les proxies résidentiels eux-mêmes comme vecteur pour créer des botnets DDoS , atteignant un pic de ~400 000 IPs exploitées en un seul jour (février-mars 2026).
Another variant, KimWolf, targets Android systems, including mobile phones and Smart TVs.
"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code.
“Beyond the C2 Takedown ... disrupting a botnet’s command-and-control infrastructure was a major step.”
“The primary path for resolution is ENS over Ethereum JSON-RPC. It picks a random public RPC node ... opens TLS to it on port 443, and issues Ethereum eth_call requests.”
“The bot first resolves its C2 from a DNS TXT dead-drop” and “dead drop domains ... update information in their TXT records with base64 and XOR encoded information to give the real backend IPs back to the bot.”
Published third-party research places malware infrastructure in SYSECT-routed prefixes: Kimwolf v7 C2 endpoints in 212.193.31.0/24; an Aisuru-matched sample contacting 147.45.44.34:8001; and a possible Sliver C2 at 89.19.220.70:4443. Bitsight also documented Aisuru/Kimwolf proxy infrastructure in ML Cloud-geofeed-declared ranges.
Ботнетот исто така има за цел да ја направи својата инфраструктура за командување и контрола (C2) поотпорна на обиди за нејзино отстранување, преку повеќеслоен механизам кој користи Ethereum Name Service (ENS) за добивање на C2-адресата, однапред вграден Tor .onion скриен сервис и локален прокси за рутирање меѓу clearnet и Tor.
“The highest measured bandwidth attack reached 2.3 Tbit/s” and “Attackers are steering their botnets with greater precision and control, generating more traffic in less time.”
“The highest measured bandwidth attack reached 2.3 Tbit/s” and “attackers used a traffic spike against two domains as cover.”
88 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
161 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Aisuru offshoot that recruits Android devices through exposed debugging services and weaknesses in residential proxy infrastructure. Supports DDoS and residential proxy abuse, with resilient blockchain-based command retrieval. The article gives conflicting status descriptions, reporting both inactivity and post-takedown reactivation.
Discussed alongside Aisuru as botnet infrastructure using compromised Android streaming devices. The guide attributes a December 2025 attack reaching 31.4 Tbps to the combined Aisuru/Kimwolf designation.
Botnet infrastructure was observed using C2 endpoints and proxy-C2 infrastructure in prefixes linked by routing or geofeed data to Media Land/ML Cloud. The content explicitly cautions that this does not establish that SYSECT or Media Land operated the malware.
Kimwolf apparaît uniquement dans la liste « Malware / Outils ».
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.