logo

The Kimwolf Botnet is Stalking Your Local Network

ID: 71f72433-2b8d-5db6-997d-b37c455f3592

STIX ID: report--71f72433-2b8d-5db6-997d-b37c455f3592

Feed Name: Krebs on Security

Threat Score
85/100

Date Published: 2026-01-02

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

This report describes the Kimwolf botnet: an active, large-scale Android-based malware campaign that has infected ~2 million devices (mainly unofficial Android TV boxes and digital photo frames) by abusing residential proxy services and device misconfigurations. Kimwolf turns compromised devices into proxy nodes for DDoS, ad fraud and account takeover, tunnels into victims' local networks by resolving domains to RFC-1918 addresses and exploiting devices with Android Debug Bridge enabled, and has been observed rebuilding rapidly after takedowns; the article includes affected provider details, device/product lists, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.