logo

史上最疯:独家揭秘感染全球180万Android设备的巨型僵尸网络Kimwolf

ID: a18650b7-4cd2-5109-ab16-957f88d557ce

STIX ID: report--a18650b7-4cd2-5109-ab16-957f88d557ce

Feed Name: QiAnXin XLab

Threat Score
88/100

Date Published: 2025-12-17

Date Updated: 2026-05-25

Author: Alex.Turing

...
...

Summary: This technical analysis documents the discovery and investigation of the Kimwolf botnet—an NDK-compiled Android malware family targeting consumer TV boxes and similar devices. Researchers observed large-scale activity (daily active IP peaks ~1.8M, conservative infection estimate >1.8M devices) and linkage to the Aisuru group; Kimwolf supports DDoS (reported participation in attacks up to ~30 Tbps), proxying, reverse shells and file management. Notable operational sophistication includes use of DNS-over-TLS, ENS (Ethereum Name Service) for resilient C2, ECDSA-based C2 verification, stack-XOR string obfuscation, and multiple downloader servers; the report provides extensive IOCs (sample hashes, domains, downloader IPs) and recommends coordination with CERTs and device hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.