Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers
ID: 432598f4-80d9-5cb3-bd02-a9eb554127ed
STIX ID: report--432598f4-80d9-5cb3-bd02-a9eb554127ed
Feed Name: CyberScoop
Kimwolf, a DDoS botnet that splintered from Aisuru, surged in late 2025—infecting over 2 million Android TV devices by abusing residential proxy networks and briefly topping Cloudflare’s domain rankings. Operators use short, high-volume DDoS bursts (Aisuru previously delivered a 29.7 Tbps attack), frequently target gaming servers like Minecraft, and rapidly shift infrastructure to evade detection; defenders (Lumen and partners) have null-routed or blocked hundreds of C2s, but the botnet remains a significant financially motivated threat with potential to cause broader disruption if repurposed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
