Kimwolf
- Malware type
- botnet, ddos
- Last IoC activity
- 2026-07-21 21:39:30
- Profile updated
- 2026-07-07 14:04:21
Targeted industries: technology-and-telecommunications
Context
KIMWOLF is an android based malware which uses compromised systems to relay malicious and abusive Internet traffic, as well as participating in distributed denial-of-service (DDoS). KIMWOLF primarily infects unofficial Android-TV set-top boxes and digital photo frames. The malware has frequently been noted to achieve infection spread via abusing Android Debug Bridge (ADB) and residential proxies. There are multiple reports suggesting a connection to the Aisuru botnet, with Kimwolf acting as the Android variant.
Reports & references
- krebsonsecurity.com — Who Operates The Badbox 2 0 Botnet (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Kimwolf (report)
- krebsonsecurity.com — The Kimwolf Botnet Is Stalking Your Local Network (report)
- securityweek.com — Kimwolf Android Botnet Grows Through Residential Proxy Networks (report)
- krebsonsecurity.com — Who Benefited From The Aisuru And Kimwolf Botnets (report)
- blog.cloudflare.com — Ddos Threat Report 2025 Q4 (report)
- infoblox.com — Kimwolf Howls From Inside The Enterprise (report)
- synthient.com — A Broken System Fueling Botnets (report)
- krebsonsecurity.com — Kimwolf Botnet Lurking In Corporate Govt Networks (report)
- blog.xlab.qianxin.com — Kimwolf Botnet En (report)