logo

Kimwolf Botnet Swamps Anonymity Network I2P

ID: 317353d5-2f0c-5b11-9f82-d54bbc3627d7

STIX ID: report--317353d5-2f0c-5b11-9f82-d54bbc3627d7

Feed Name: Krebs on Security

Threat Score
80/100

Date Published: 2026-02-11

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

The Kimwolf IoT botnet, which has infected millions of poorly secured devices, has been actively used for large-scale DDoS attacks and recently attempted to use anonymity networks (notably I2P, and tested Tor) as fallback command-and-control channels. Around February 3, a massive number of Kimwolf-infected routers (reportedly hundreds of thousands) tried to join I2P, overwhelming and degrading the network (a Sybil-like impact) and revealing the botnet operators' experiments to harden C2 resilience; the botnet has also previously manipulated DNS usage to affect major domains and appears to be actively evolving.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.