logo

Who Benefited from the Aisuru and Kimwolf Botnets?

ID: c15913be-1873-5dbc-88b8-3df26761a51d

STIX ID: report--c15913be-1873-5dbc-88b8-3df26761a51d

Feed Name: Krebs on Security

Threat Score
78/100

Date Published: 2026-01-08

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Kimwolf (and its predecessor Aisuru) is a large-scale botnet that has mass-compromised millions of unofficial Android TV streaming boxes to run DDoS attacks and provide residential proxy services. The investigation links the botnet to specific operators and commercial services (Resi Rack, Plainproxies/ByteConnect, Maskify, 3XK Tech), identifies infrastructure (e.g., IP 93.95.112.59) and abuse patterns (credential stuffing, ad fraud, scraping), and documents attacker resilience measures such as using Ethereum Name Service (ENS) for dynamic control-server discovery; owners of impacted devices are advised to remove vulnerable boxes from networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.