BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Massive Kimwolf Botnet Hijacks 1.8M Android TVs for DDoS Attack

Kimwolf: A Powerful Android Botnet Infecting 1.8 Million Devices with Advanced DDoS, Proxy, and Blockchain Techniques

  • A new Android-based botnet called Kimwolf has compromised 1.8 million devices such as smart TVs, set-top boxes, and tablets worldwide.
  • Between November 19 and 22, 2025, Kimwolf issued 1.7 billion distributed denial-of-service (DDoS) commands targeting countries including the U.S., China, France, Germany, and Canada.
  • The botnet uses advanced methods like proxy forwarding, reverse shell access, and encrypted communications, integrating Ethereum Name Service (ENS) for resilience.
  • Kimwolf appears linked to the AISURU botnet, sharing infection scripts and code, indicating they are operated by the same Hacker group.
  • Most commands focus on creating proxy services to monetize bandwidth, deploying a Rust-based Command Client and ByteConnect software development kit on infected devices.

A large-scale DDoS botnet named Kimwolf has infected approximately 1.8 million Android-based devices including TVs, set-top boxes, and tablets. This was reported following investigations conducted between October and December 2025. The botnet commanded a remarkable 1.7 billion attack instructions over three days from November 19 to 22, 2025. Infected devices are primarily found in Brazil, India, the U.S., Argentina, South Africa, and the Philippines.

- Advertisement -

Kimwolf was created using the Android Native Development Kit (NDK), providing it capabilities beyond typical DDoS attacks. It supports proxy forwarding, reverse shell execution (a method allowing remote control), and file management. The Malware connects to command-and-control (C2) servers, which it obtains using DNS-over-TLS for encrypted DNS requests. Researchers managed to seize control of one of these domains and found it briefly topped Cloudflare’s top 100 domains list, even surpassing Google during the attack period.

The infected devices mostly include models such as TV BOX, SuperBOX, HiDPTAndroid, P200, X96Q, XBOX, SmartTV, and MX10. While the exact infection method is unclear, the botnet’s infrastructure has adapted to disruptions by using Ethereum Name Service (ENS), leveraging smart contracts to obtain C2 IP addresses. This technique, called EtherHiding, adds resilience against takedown efforts by encrypting C2 details within Ethereum blockchain transactions.

Kimwolf is strongly associated with the AISURU botnet, which has launched major DDoS attacks over the past year. Both botnets share infection scripts and code, sometimes even the same digital signature certificate (“John Dinglebert Dinglenut VIII VanSack Smith”), confirming they belong to the same threat actor. A downloader server identified on December 8, 2025, contained scripts referencing both botnets.

The malware ensures only one active process runs per device and supports 13 different types of DDoS attacks over UDP, TCP, and ICMP protocols. Over 96% of issued commands are proxy-related, indicating the attackers’ focus on exploiting bandwidth for profit. To build and manage the proxy network, the botnet deploys a Rust-based Command Client and distributes ByteConnect SDK, a tool that helps monetize app and IoT traffic.

- Advertisement -

The rise of Kimwolf marks a shift from earlier malware mainly targeting IoT devices like routers and cameras, with attackers increasingly focusing on smart TVs and related devices globally.

For further details, see the original research report and related VirusTotal samples. The Ethereum smart contract involved is accessible here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Soars Past Key Resistance; Traders See 69% Chance of $84K

Bitcoin surged 2.7%, breaking a key descending resistance line that had suppressed its price...

$650M In Shorts Liquidated Amid Bitcoin Surge

Over $800 million in crypto positions were liquidated in 24 hours as Bitcoin surged...

Tether-backed firms Northern Data and Rumble begin merger

Tether-owned companies Northern Data and Rumble have commenced their merger, giving Rumble access to...

Bitcoin Hits 10-Week High as Trader Targets $88K Rally

<div✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant...

VeBetter’s AI Validates Sustainability on Blockchain

The VeBetter platform has integrated AI since its 2024 launch to verify sustainable actions...

Must Read

Forex Trading Vs Crypto Trading: Which One Should You Choose?

So you're trying to decide between two types of trading: Forex and cryptocurrency.Forex trading is the big player in the trading world, with lots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading