Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices

‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices

Posted on December 19, 2025December 19, 2025 By CWS

A newly recognized Android botnet has contaminated over 1.8 million gadgets and might launch huge distributed denial-of-service (DDoS) assaults, Chinese language cybersecurity agency XLab warns.

Dubbed Kimwolf, the botnet has proxy forwarding, reverse shell, and file administration capabilities. 

The risk seems linked to Aisuru, the TurboMirai-class IoT botnet lately blamed for a record-breaking 29.7 Tbps DDoS assault.

Kimwolf, XLab says, is especially targeted on site visitors proxying, however was noticed issuing over 1.7 billion DDoS assault instructions between November 19 and 22.

This pushed its command-and-control (C&C) area, 14emeliaterracewestroxburyma02132[.]su, to the highest place in Cloudflare’s world area recognition rankings, surpassing google.com.

The malware, the cybersecurity agency says, depends on the DNS over TLS (DoT) protocol to encapsulate DNS requests and evade detection, and makes use of a signature verification mechanism to validate communication directions.

Kimwolf primarily infects Android TV set-top containers deployed on residential networks, with the ensnared gadgets distributed throughout greater than 220 international locations and areas.

Because of dynamic IP allocation mechanisms and the worldwide unfold of the contaminated gadgets, the precise dimension of the botnet will not be recognized.Commercial. Scroll to proceed studying.

In keeping with XLab, C&C domains related to the botnet have been taken down by third events not less than thrice, which compelled its builders to harden the infrastructure utilizing ENS (Ethereum Identify Service) domains.

The cybersecurity agency says it believes the botnet has been concerned in not less than two large-scale DDoS assaults, together with the near-30 Tbps incident flagged earlier this month.

Whereas a number of current huge DDoS assaults have been attributed to Aisuru, XLab believes that Kimwolf might need been the lead botnet in these incidents.

“Though we can not straight measure it, via observations of two large-scale DDoS occasions and a horizontal comparability with Aisuru, we imagine Kimwolf’s assault functionality is near 30Tbps,” XLab notes.

The Chinese language agency has analyzed a number of Kimwolf samples collected since October, uncovering the malware’s reference to Aisuru, hyperlinks to the ByteConnect SDK monetization resolution, and a number of references to the cybersecurity journalist Brian Krebs that the Kimwolf developer left within the code.

Associated: Report-Breaking DDoS Assault Peaks at 22 Tbps and 10 Bpps

Associated: ShadowV2 DDoS Service Lets Prospects Self-Handle Assaults

Associated: New ‘Broadside’ Botnet Poses Danger to Delivery Corporations

Associated: RondoDox Botnet Takes ‘Exploit Shotgun’ Method

Security Week News Tags:Android, Botnet, Devices, Ensnares, Kimwolf, Million

Post navigation

Previous Post: New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild
Next Post: University of Sydney Data Breach Affects 27,000 Individuals 

Related Posts

MITRE Posts Results of 2025 ATT&CK Enterprise Evaluations MITRE Posts Results of 2025 ATT&CK Enterprise Evaluations Security Week News
Investor Lawsuit Over CrowdStrike Outage Dismissed Investor Lawsuit Over CrowdStrike Outage Dismissed Security Week News
Personal Information Compromised in Freedom Mobile Data Breach Personal Information Compromised in Freedom Mobile Data Breach Security Week News
New Firefox Extensions Required to Disclose Data Collection Practices New Firefox Extensions Required to Disclose Data Collection Practices Security Week News
Washington Post Says Nearly 10,000 Employees Impacted by Oracle Hack Washington Post Says Nearly 10,000 Employees Impacted by Oracle Hack Security Week News
New Campaigns Distribute Malware via Open Source Hacking Tools New Campaigns Distribute Malware via Open Source Hacking Tools Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News