logo

Kimwolf Howls from Inside the Enterprise

ID: 149d3b3e-9dc0-5289-afff-9a56cca86761

STIX ID: report--149d3b3e-9dc0-5289-afff-9a56cca86761

Feed Name: Infoblox Threat Intel Blog

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-28

Author: Renée Burton

...
...

The report documents active Kimwolf botnet activity that abuses residential proxy services and compromised endpoints to probe local networks via DNS queries. Infoblox Threat Defense Cloud telemetry shows queries to Kimwolf domains from nearly 25% of customers across multiple industries, indicating widespread scanning (though few confirmed enterprise compromises); the report lists observed malicious domains, abused proxy endpoints (e.g., IPIDEA, Plainproxies/Byteconnect), and recommends blocking/resolving protective DNS policies and searching DNS logs for the indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.