logo

Kimwolf Botnet Exploits 2 Million Devices to Build a Global Proxy Infrastructure

ID: 38538649-c683-54c3-bbc4-99a1c5d49acf

STIX ID: report--38538649-c683-54c3-bbc4-99a1c5d49acf

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report details the Kimwolf botnet that has compromised more than two million devices worldwide by leveraging preinstalled malware on cheap Android TV boxes and a flaw in residential proxy providers that permits upstream access into users' local networks; compromised devices with ADB enabled are turned into residential proxies used for DDoS, ad fraud, scraping and account takeover, and although providers have patched the exploited proxy flaw, the botnet continues to rebuild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.