Kimwolf Howls from Inside the Enterprise
ID: 149d3b3e-9dc0-5289-afff-9a56cca86761
STIX ID: report--149d3b3e-9dc0-5289-afff-9a56cca86761
Feed Name: Infoblox Threat Intel Blog
The report documents active Kimwolf botnet activity that abuses residential proxy services and compromised endpoints to probe local networks via DNS queries. Infoblox Threat Defense Cloud telemetry shows queries to Kimwolf domains from nearly 25% of customers across multiple industries, indicating widespread scanning (though few confirmed enterprise compromises); the report lists observed malicious domains, abused proxy endpoints (e.g., IPIDEA, Plainproxies/Byteconnect), and recommends blocking/resolving protective DNS policies and searching DNS logs for the indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
