Researchers reported that the Kimwolf botnet has evolved from a massive Android malware operation previously tied to roughly 1.8 million infected devices into a new v7 variant focused on Android TV boxes and set-top boxes. The newer strain was discovered targeting exposed devices through unauthenticated Android Debug Bridge (ADB) access on local networks, with propagation aided by abuse of residential proxy services. Investigators said the malware now appears to separate initial compromise from later bot activity, with external loaders handling installation while the bot binary concentrates on distributed denial-of-service and proxy relay functions.
Analysis of Kimwolf v7 found upgraded attack and resilience features, including an HTTP/2 flood capability designed to mimic realistic browser fingerprints and a more durable command-and-control scheme using Ethereum Name Service (ENS) resolution, a Tor .onion fallback, and a local proxy architecture. Researchers also linked the botnet to clustered C2 infrastructure in AS202799 in Saint Petersburg, Russia, and identified eth.rpcuniverse[.]com as a likely operator-controlled RPC facade, indicating continued investment in infrastructure intended to keep the botnet operational and harder to disrupt.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
An international law-enforcement operation in March 2026 disrupted previous versions of the Kimwolf botnet and ended with seizure of its infrastructure. Unit 42 said the newer version had appeared about a month earlier, reducing the impact of conventional takedown measures.
Unit 42 discovered the Kimwolf v7 Android/IoT botnet variant on February 3, 2026. The version primarily targets Android TV boxes and set-top boxes and adds updated DDoS and C2 capabilities.
Unit 42 identified 212.193.31[.]102 as the first observed host in a Kimwolf-related SSH-key cluster of infrastructure in AS202799, geolocated to Saint Petersburg, Russia.
Unit 42 said Kimwolf's infrastructure suffered two domain takedowns in December 2025, prompting the botnet's later three-tier command-and-control resolution design for resilience.
Unit 42 identified eight Android APK artifacts linked to Kimwolf between October and December 2025. The APKs masqueraded as a system service, probed for root access, and executed a bundled ELF payload to help propagate the botnet on Android devices.
Around August 2025, the operators transitioned from the Linux-focused AISURU codebase to the Android-targeting Kimwolf codebase, focusing on Android TV boxes and set-top boxes.
Unit 42 reported that the botnet operators were active starting in August 2024, initially tracking the operation as AISURU when it targeted Linux IoT devices.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcesecurityaffairs.com
Open sourcecyberscoop.com
Open sourcethehackernews.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.xlab.qianxin.com
Open sourceradar.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.