logo

Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices

ID: 029686f4-c50d-5943-8cd7-5af7a0d2653a

STIX ID: report--029686f4-c50d-5943-8cd7-5af7a0d2653a

Feed Name: QiAnXin XLab

Threat Score
92/100

Date Published: 2025-12-17

Date Updated: 2026-05-25

Author: Wang Hao

...
...

This report documents the Kimwolf botnet — an Android TV-box focused malware family linked to the Aisuru group — describing its scale (estimated >1.8M infected devices, observed peaks ~1.83M daily IPs), capabilities (DDoS up to ~30 Tbps, proxying, reverse shell, file management), advanced evasions (DNS-over-TLS, ENS-based EtherHiding, elliptic-curve signature-based C2 auth), and provides technical reverse-engineering details plus IOCs (file hashes, domains, downloader IPs) to support mitigation and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.