Kimwolf

Malware type
botnet, ddos
Last IoC activity
2026-07-21 21:39:30
Profile updated
2026-07-07 14:04:21

Targeted industries: technology-and-telecommunications

Context

KIMWOLF is an android based malware which uses compromised systems to relay malicious and abusive Internet traffic, as well as participating in distributed denial-of-service (DDoS). KIMWOLF primarily infects unofficial Android-TV set-top boxes and digital photo frames. The malware has frequently been noted to achieve infection spread via abusing Android Debug Bridge (ADB) and residential proxies. There are multiple reports suggesting a connection to the Aisuru botnet, with Kimwolf acting as the Android variant.

Reports & references

  • krebsonsecurity.com — Who Operates The Badbox 2 0 Botnet (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Kimwolf (report)
  • krebsonsecurity.com — The Kimwolf Botnet Is Stalking Your Local Network (report)
  • securityweek.com — Kimwolf Android Botnet Grows Through Residential Proxy Networks (report)
  • krebsonsecurity.com — Who Benefited From The Aisuru And Kimwolf Botnets (report)
  • blog.cloudflare.com — Ddos Threat Report 2025 Q4 (report)
  • infoblox.com — Kimwolf Howls From Inside The Enterprise (report)
  • synthient.com — A Broken System Fueling Botnets (report)
  • krebsonsecurity.com — Kimwolf Botnet Lurking In Corporate Govt Networks (report)
  • blog.xlab.qianxin.com — Kimwolf Botnet En (report)

External references