logo

Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide

ID: 512c860d-3573-52b8-b569-582de0c5284b

STIX ID: report--512c860d-3573-52b8-b569-582de0c5284b

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A security report on the Kimwolf Android botnet: a sophisticated, NDK-compiled malware family that has compromised roughly 1.8 million Android devices across 222 countries. Kimwolf persists via an APK that drops a native binary, uses Unix domain sockets to enforce single instances, decrypts embedded C2 domains, communicates over DNS-over-TLS and TLS with a custom handshake and ECC signature verification, and supports 13 DDoS methods; researchers observed it issuing 1.7 billion DDoS commands over a short period.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.