logo

Kimwolf Howls from Inside the Enterprise

ID: 42b1fc98-b4b5-55cb-bf54-f35864cd26d6

STIX ID: report--42b1fc98-b4b5-55cb-bf54-f35864cd26d6

Feed Name: Infoblox Blog

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-28

Author: Renée Burton

...
...

Infoblox telemetry analysis shows the Kimwolf botnet actively abusing residential proxy services to scan enterprise and institutional networks for vulnerable local devices (notably Android TVs), with nearly 25% of Threat Defense Cloud customers having at least one query to Kimwolf-associated domains; the report includes observed domains and proxy endpoints, industry distribution, temporal activity, and recommends protective DNS, blocking suspicious/bogon responses, and reviewing DNS logs for related indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.