logo

Kimwolf Botnet Lurking in Corporate, Govt. Networks

ID: 8f19ff60-e395-52c2-9f6f-8bba6f3380a5

STIX ID: report--8f19ff60-e395-52c2-9f6f-8bba6f3380a5

Feed Name: Krebs on Security

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

**Kimwolf** is an active IoT botnet that has infected millions of devices by abusing residential proxy services and Android TV streaming boxes (many shipped with proxy malware preinstalled), enabling large-scale DDoS attacks and relaying various malicious traffic; telemetry from Infoblox, Synthient, and Spur shows significant presence across government, education, healthcare, and corporate networks worldwide, making lateral pivoting from compromised proxy endpoints a practical threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.