Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide
ID: 512c860d-3573-52b8-b569-582de0c5284b
STIX ID: report--512c860d-3573-52b8-b569-582de0c5284b
Feed Name: cybersecurityNews.com
A security report on the Kimwolf Android botnet: a sophisticated, NDK-compiled malware family that has compromised roughly 1.8 million Android devices across 222 countries. Kimwolf persists via an APK that drops a native binary, uses Unix domain sockets to enforce single instances, decrypts embedded C2 domains, communicates over DNS-over-TLS and TLS with a custom handshake and ECC signature verification, and supports 13 DDoS methods; researchers observed it issuing 1.7 billion DDoS commands over a short period.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
