KimWolf is an Android- and IoT-focused botnet associated with the AISURU lineage and used primarily for distributed denial-of-service operations. Activity under the broader lineage dates to at least 2024, with operators shifting from Linux IoT targeting toward Android devices in 2025, especially Android TV boxes and set-top devices. KimWolf has also been described as a DDoS-for-hire platform, with law-enforcement actions in 2026 alleging its use in large-scale attacks worldwide and linking it to the operator alias Dort.
KimWolf primarily compromises Android TV and related embedded devices exposed through Android Debug Bridge, often by abusing residential proxy networks to tunnel into local networks and reach devices that are not directly internet-facing. Reported Android delivery chains have included APKs masquerading as system services and wrappers that check for root access before launching embedded ELF payloads. Recent versions appear to have separated propagation from the main bot payload, with the core binary focused on attack execution and traffic relaying rather than scanning, exploitation, or brute-force infection logic.
The malware’s core functionality centers on DDoS attacks and proxy-style relay behavior. Reported capabilities include multiple network- and application-layer flood methods, including UDP, TLS/HTTPS, and HTTP/2 floods. Version 7 notably added an HTTP/2 flood implementation designed to mimic legitimate Chrome-like browser fingerprints and header behavior, complicating traffic filtering and mitigation. The malware has also been reported to support reverse-shell and file-management functions in earlier Android-focused reporting, though newer analyses emphasize DDoS and relay roles as the primary mission.
KimWolf has evolved its command-and-control architecture to improve resilience against disruption. Reported versions use Ethereum Name Service resolution through public blockchain RPC infrastructure, a local proxy layer, and a Tor hidden-service fallback to maintain controller reachability and resist conventional takedowns. The malware also disguises itself as legitimate Android system processes to reduce visibility on infected devices.
Targeting has centered on consumer and small-office connected devices, particularly Android TV boxes, streaming devices, webcams, digital photo frames, and other IoT systems. The botnet has been linked to very large attack volumes and extensive global victimization, and authorities have tied it to coordinated multinational disruption efforts against KimWolf, AISURU, and related botnets in 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
„Најраниот пронајден примерок, кој ја таргетира x86 архитектурата со експлоатација на Dirty COW , укажува дека оваа фамилија еволуирала од традиционална Linux експлоатација кон актуелниот Android модел на ширење базиран на ADB“ | Истражувачи за сајбер-безбедност открија нова верзија на Android и Internet of Things (IoT) ботнетот Kimwolf/AISURU, која носи значителни подобрувања за зголемување на оперативната отпорност и за изведување дистрибуирани напади за одбивање на услугата (DDoS).
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Menace émergente : Kimwolf/Dort # L’acteur individuel Dort a introduit une nouvelle menace en exploitant les proxies résidentiels eux-mêmes comme vecteur pour créer des botnets DDoS , atteignant un pic de ~400 000 IPs exploitées en un seul jour (février-mars 2026).
Another variant, KimWolf, targets Android systems, including mobile phones and Smart TVs.
"The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0"
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code.
The biggest change, according to the report, is a new flood method built on HTTP/2, the protocol that carries most web traffic today.
Потоа инсталира малициозен софтвер способен за изведување DDoS напади и за претворање на уредот во реле преку кое се пренасочува злонамерен сообраќај.
Ботнетот исто така има за цел да ја направи својата инфраструктура за командување и контрола (C2) поотпорна на обиди за нејзино отстранување, преку повеќеслоен механизам кој користи Ethereum Name Service (ENS) за добивање на C2-адресата, однапред вграден Tor .onion скриен сервис и локален прокси за рутирање меѓу clearnet и Tor.
Menace émergente : Kimwolf/Dort ... exploitant les proxies résidentiels eux-mêmes comme vecteur pour créer des botnets DDoS
The botnet has been active under related names since 2024... Each compromised box can be directed to send traffic at a chosen target... Kimwolf v7 introduces an HTTP/2 flood that builds full Chrome-like browser fingerprints before sending requests.
Некои од новите функции забележани во оваа верзија се: Изведување HTTP/2 flood напади со користење на библиотеката nghttp2, заедно со создавање целосни отпечатоци на прелистувач кои го имитираат однесувањето на легитимните прелистувачи на ниво на протокол и HTTP заглавија.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
146 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mirai descendant mentioned as background context regarding prior law-enforcement action.
A botnet malware family targeting Android TV boxes and set-top devices, used primarily for distributed denial-of-service attacks and traffic relaying. The v7 variant adds HTTP/2 flooding with Chrome-like browser fingerprints, a tuned UDP flood for ARM devices, and resilient command-and-control using blockchain RPC lookups, a local proxy, and Tor fallback.
Android and IoT botnet focused on DDoS attacks and proxy relay. The v7 variant adds HTTP/2 flood capability with browser fingerprinting to better mimic legitimate traffic, uses ENS and a Tor hidden service for resilient C2 resolution, and targets Android TV devices via exposed ADB while the Linux AISURU variant focuses on Linux IoT devices.
Android TV botnet targeting Android TV boxes and set-top boxes. It is used as a large-scale DDoS platform, adds an HTTP/2 flood that mimics Chrome browser fingerprints, uses Ethereum Name Service and Tor-backed C2 resilience, can act as a relay/proxy, and spreads via exposed Android Debug Bridge on port 5555.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.