logo

Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers

ID: 432598f4-80d9-5cb3-bd02-a9eb554127ed

STIX ID: report--432598f4-80d9-5cb3-bd02-a9eb554127ed

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2026-01-14

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Kimwolf, a DDoS botnet that splintered from Aisuru, surged in late 2025—infecting over 2 million Android TV devices by abusing residential proxy networks and briefly topping Cloudflare’s domain rankings. Operators use short, high-volume DDoS bursts (Aisuru previously delivered a 29.7 Tbps attack), frequently target gaming servers like Minecraft, and rapidly shift infrastructure to evade detection; defenders (Lumen and partners) have null-routed or blocked hundreds of C2s, but the botnet remains a significant financially motivated threat with potential to cause broader disruption if repurposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.