logo

Kimwolf Android botnet abuses residential proxies to infect internal devices

ID: d529ecd5-0555-57ae-aca0-4dbf8e54a351

STIX ID: report--d529ecd5-0555-57ae-aca0-4dbf8e54a351

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-01-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report details the Kimwolf (Aisuru) Android botnet’s rapid growth to nearly two million compromised devices by scanning and exploiting residential proxy networks that expose unauthenticated ADB services; attackers deliver payloads via netcat/telnet to install bot payloads used for massive DDoS (noted as the largest publicly disclosed at 29.7 Tbps), proxy resale, and ad/sdk monetization, and researchers recommend blocking local network access on proxy providers, replacing or wiping infected devices, and avoiding low-cost/unverified Android TV boxes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.