BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Massive Kimwolf Botnet Hijacks 1.8M Android TVs for DDoS Attack

Kimwolf: A Powerful Android Botnet Infecting 1.8 Million Devices with Advanced DDoS, Proxy, and Blockchain Techniques

  • A new Android-based botnet called Kimwolf has compromised 1.8 million devices such as smart TVs, set-top boxes, and tablets worldwide.
  • Between November 19 and 22, 2025, Kimwolf issued 1.7 billion distributed denial-of-service (DDoS) commands targeting countries including the U.S., China, France, Germany, and Canada.
  • The botnet uses advanced methods like proxy forwarding, reverse shell access, and encrypted communications, integrating Ethereum Name Service (ENS) for resilience.
  • Kimwolf appears linked to the AISURU botnet, sharing infection scripts and code, indicating they are operated by the same Hacker group.
  • Most commands focus on creating proxy services to monetize bandwidth, deploying a Rust-based Command Client and ByteConnect software development kit on infected devices.

A large-scale DDoS botnet named Kimwolf has infected approximately 1.8 million Android-based devices including TVs, set-top boxes, and tablets. This was reported following investigations conducted between October and December 2025. The botnet commanded a remarkable 1.7 billion attack instructions over three days from November 19 to 22, 2025. Infected devices are primarily found in Brazil, India, the U.S., Argentina, South Africa, and the Philippines.

- Advertisement -

Kimwolf was created using the Android Native Development Kit (NDK), providing it capabilities beyond typical DDoS attacks. It supports proxy forwarding, reverse shell execution (a method allowing remote control), and file management. The Malware connects to command-and-control (C2) servers, which it obtains using DNS-over-TLS for encrypted DNS requests. Researchers managed to seize control of one of these domains and found it briefly topped Cloudflare’s top 100 domains list, even surpassing Google during the attack period.

The infected devices mostly include models such as TV BOX, SuperBOX, HiDPTAndroid, P200, X96Q, XBOX, SmartTV, and MX10. While the exact infection method is unclear, the botnet’s infrastructure has adapted to disruptions by using Ethereum Name Service (ENS), leveraging smart contracts to obtain C2 IP addresses. This technique, called EtherHiding, adds resilience against takedown efforts by encrypting C2 details within Ethereum blockchain transactions.

Kimwolf is strongly associated with the AISURU botnet, which has launched major DDoS attacks over the past year. Both botnets share infection scripts and code, sometimes even the same digital signature certificate (“John Dinglebert Dinglenut VIII VanSack Smith”), confirming they belong to the same threat actor. A downloader server identified on December 8, 2025, contained scripts referencing both botnets.

The malware ensures only one active process runs per device and supports 13 different types of DDoS attacks over UDP, TCP, and ICMP protocols. Over 96% of issued commands are proxy-related, indicating the attackers’ focus on exploiting bandwidth for profit. To build and manage the proxy network, the botnet deploys a Rust-based Command Client and distributes ByteConnect SDK, a tool that helps monetize app and IoT traffic.

- Advertisement -

The rise of Kimwolf marks a shift from earlier malware mainly targeting IoT devices like routers and cameras, with attackers increasingly focusing on smart TVs and related devices globally.

For further details, see the original research report and related VirusTotal samples. The Ethereum smart contract involved is accessible here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin reclaims market cap lead over Tesla

Bitcoin's market cap of $1.62 trillion has narrowly overtaken Tesla's $1.608 trillion, making it...

Bitcoin Eyes $81K as Traders Brace for Sub-$80K Retest

Bitcoin traders anticipate a pullback to retest the $80,000 support level and the bull...

AI Models Play “Survivor” in Stanford Game Benchmark

A Stanford researcher created an AI "Survivor" game called Agent Island to test how...

Macro Forces Drive Bitcoin, Not Corporate Buying

Strategy will never be a net seller of Bitcoin, but may sell to fund...

Trump Media Posts $406M Loss on Bitcoin Downturn

Trump Media & Technology Group reported a massive net loss of $405.9 million in...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading