Kimwolf Howls from Inside the Enterprise
ID: 42b1fc98-b4b5-55cb-bf54-f35864cd26d6
STIX ID: report--42b1fc98-b4b5-55cb-bf54-f35864cd26d6
Feed Name: Infoblox Blog
Infoblox telemetry analysis shows the Kimwolf botnet actively abusing residential proxy services to scan enterprise and institutional networks for vulnerable local devices (notably Android TVs), with nearly 25% of Threat Defense Cloud customers having at least one query to Kimwolf-associated domains; the report includes observed domains and proxy endpoints, industry distribution, temporal activity, and recommends protective DNS, blocking suspicious/bogon responses, and reviewing DNS logs for related indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
