logo

Kimwolf botnet leverages residential proxies to hijack 2M+ Android devices

ID: 2099173b-23d0-5faa-9d71-9f2ee622be7f

STIX ID: report--2099173b-23d0-5faa-9d71-9f2ee622be7f

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-01-05

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

The Kimwolf Android botnet has infected an estimated >2 million devices—primarily insecure Android TV boxes and devices in residential proxy pools—by exploiting exposed ADB and insecure proxy SDKs. Operators use the botnet for large-scale DDoS, proxying/reselling bandwidth, and credential-stuffing; the malware employs evasion and resilience techniques (DoT, ECC-signed C2, EtherHiding/ENS domains) and has global reach with heavy concentrations in Vietnam, Brazil, India, and Saudi Arabia. Researchers recommend proxy providers block risky ports, take down C2 infrastructure, and for users to wipe or destroy compromised devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.