Lumen Technologies Null-Routes Over 550 Kimwolf and Aisuru Botnet Servers
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The Black Lotus Labs team at Lumen Technologies reported null-routing traffic to over 550 command-and-control (C2) nodes linked to the AISURU and Kimwolf botnets since early October 2025. These botnets have emerged as significant threats, particularly affecting Android devices, with Kimwolf infecting over 2 million devices by exploiting vulnerabilities in Android TV streaming devices.
Details about Kimwolf surfaced in late 2025 when QiAnXin XLab published an analysis revealing that the malware turns compromised devices into residential proxies. This is achieved by delivering a software development kit (SDK) called ByteConnect through untrustworthy apps, allowing the botnet to expand its reach.
In September 2025, Black Lotus Labs identified residential SSH connections from Canadian IP addresses related to Aisuru’s backend C2. The botnet’s infrastructure has been linked to various proxy services, including a domain associated with a Utah-based hosting provider, Resi Rack LLC, which has been implicated in selling proxy services.
In early October 2025, a notable increase in Kimwolf bots was observed, with a 300% surge in new bots added over a week, reaching a total of 800,000 by mid-month. This spike was attributed to a single residential proxy service where many of the bots were listed for sale.
The botnet’s C2 architecture was found to exploit security flaws in proxy services, allowing it to interact with devices on internal networks and drop malware. This behavior underscores the growing trend of adversaries leveraging consumer devices for malicious activities.
Implications for Cybersecurity
The rise of botnets like AISURU and Kimwolf illustrates the increasing sophistication of cyber threats targeting everyday devices. Users should be vigilant about the security of their devices, especially those connected to the internet.
Organizations must monitor for unusual traffic patterns and ensure their devices are updated and secured against known vulnerabilities. The use of residential proxies complicates detection efforts, as malicious traffic can blend in with legitimate user activity.
As these botnets continue to evolve, it is crucial for both users and organizations to adopt proactive security measures to mitigate risks associated with compromised devices and DDoS attacks.
Key Takeaways
- Regularly update your Android devices to protect against vulnerabilities that could be exploited by botnets.
- Monitor your network for unusual traffic patterns that may indicate a compromised device.
- Be cautious when installing apps from untrusted sources, as they may contain malware.
- Consider using security software that can detect and block malicious activity on your devices.
- Educate yourself about the risks of residential proxy services and how they can be exploited by threat actors.
Key Terms & Concepts
- Botnet: In this article, a botnet refers to a network of compromised devices that can be controlled remotely to perform malicious activities.
- DDoS Attack: A DDoS attack is a malicious attempt to disrupt the normal functioning of a targeted server, service, or network by overwhelming it with a flood of internet traffic.
- Residential Proxy: A residential proxy is an IP address provided by an Internet Service Provider (ISP) that is associated with a physical device, allowing users to mask their identity online.
- Malware: Malware refers to malicious software designed to harm, exploit, or otherwise compromise a computer system or network.
- Android Debug Bridge (ADB): ADB is a versatile command-line tool that allows developers to communicate with an Android device for debugging and development purposes.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.