Quick Summary
The Securityish Brief
The Kimwolf botnet has rapidly infected more than two million devices, particularly targeting unofficial Android TV streaming boxes. This botnet, which emerged in late 2025, forces infected devices to engage in distributed denial-of-service (DDoS) attacks and relay malicious internet traffic for residential proxy services. The Chinese security firm XLab published a report on December 17, 2025, confirming that Kimwolf shares the same cybercriminal infrastructure as the Aisuru botnet, which had already been enslaving devices for similar malicious activities.
XLab’s investigation revealed that both Kimwolf and Aisuru were deployed using the same internet address, indicating a shared origin. The report highlighted that the malicious software often bundled with mobile apps and games turns devices into residential proxies, which are then exploited for ad fraud and account takeover attempts. This exploitation is particularly concerning as many of the targeted devices lack basic security protections.
Key Players in the Kimwolf Botnet
Among the entities involved, Resi Rack LLC, a Utah-based company, has been implicated as a hosting provider for the botnet’s operations. Resi Rack’s co-founder Cassidy Hales acknowledged that they received a notification about Kimwolf using their network and expressed disappointment over the association. Additionally, the resi[.]to Discord server, where proxy services were marketed, played a role in facilitating the botnet’s activities.
Other notable players include Plainproxies, which offers a software development kit called ByteConnect, and Maskify, which advertises low-cost residential proxy services. Synthient, a startup tracking proxy services, reported that Kimwolf proxies were linked to credential-stuffing attacks targeting popular online platforms. The involvement of these companies raises questions about the ethical sourcing of proxy services and the potential for abuse.
The botmasters behind Kimwolf, identified as “Dort” and “Snow,” have been active in the cybercrime community, with reports suggesting they control millions of infected devices. The Kimwolf operators have also upgraded their infrastructure to utilize the Ethereum Name Service (ENS), allowing them to evade takedown efforts by updating control server addresses dynamically.
This situation highlights the urgent need for users and organizations to be vigilant about the devices connected to their networks. Infected Android TV boxes pose a significant risk, as they can be easily compromised and used for malicious activities. Users are advised to remove any such devices from their networks to mitigate potential harm.
Key Takeaways
- Check your network for unofficial Android TV streaming boxes and remove them if found.
- Monitor your internet traffic for unusual activity that may indicate a compromised device.
- Educate friends and family about the risks associated with using unverified streaming devices.
- Consider using a firewall or network monitoring tool to detect unauthorized traffic.
- Stay informed about the latest cybersecurity threats and best practices to protect your devices.
Key Terms & Concepts
- Kimwolf: In this article, Kimwolf refers to a botnet that has infected over two million devices, primarily targeting Android TV streaming boxes.
- Aisuru: Aisuru is an earlier botnet that shares infrastructure and operators with Kimwolf, also used for DDoS attacks and proxy services.
- Residential proxy: A residential proxy is an IP address provided by an Internet Service Provider (ISP) that allows users to route their internet traffic through it.
- DDoS attack: A DDoS attack is a malicious attempt to disrupt the normal functioning of a targeted server, service, or network by overwhelming it with traffic.
- ENS: ENS, or Ethereum Name Service, is a distributed system that allows users to register human-readable names for Ethereum addresses, which can help in locating control servers for botnets.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.