One of the largest and most sophisticated botnets ever recorded in the Android has begun to worry the global cybersecurity community. The malware, codenamed Kimwolf, is now considered one of the most serious threats, as it has managed to infect approximately 1.8 million Android devices worldwide.

From smartphones to smart TVs
Kimwolf is not limited to classic mobile phones. Instead, it targets a wide range of Android-based devices, such as smart TVs, set-top boxes, tablets, and embedded systems. This makes it particularly dangerous, as many of these devices remain active 24/7 and often do not receive regular security updates.
See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet
The discovery of the botnet
Security researchers first discovered Kimwolf in October 2025, when a trusted community contributor provided an initial sample. What was particularly striking was that the malware communicated with a command and control (C2) domain, which at the time was ranked second globally in popularity according to Cloudflare statistics – a choice that helped the botnet “get lost” in the vast volume of legitimate traffic.

Global expansion without borders
The geographic reach of Kimwolf is impressive. Infected devices are found in 222 countries and regions , with the largest concentrations recorded in Brazil (14.63%) , India (12.71%) , and the United States (9.58%) . This distribution across different time zones makes it significantly more difficult for security analysts to continuously monitor and respond promptly .
A botnet designed for cyber warfare
According to analysts at Xlab Qianxin , Kimwolf is a highly sophisticated botnet, written using the Android NDK , which makes it highly performant and difficult to analyze. In addition to classic DDoS attacks, it also has proxy forwarding , reverse shell , and file management capabilities , turning each infected device into a fully controlled attack node.
See also: Aisuru botnet behind 29.7 Tbps DDoS attack
Advanced concealment techniques
One of the most concerning features of Kimwolf is its evasion techniques. The malware uses DNS over TLS (DoT) to communicate, bypassing traditional network surveillance systems. It also uses elliptic-curve-based digital signaturesto ensure that only authentic commands from C2 servers can be executed.
How it infects and remains on devices
The infection mechanism is based on an APK file, which decompresses and executes a native binary disguised as a legitimate system service . A Unix domain socket is then created with a name related to the botnet version to ensure that multiple instances are not running simultaneously.
Kimwolf decrypts embedded C2 domains and uses the DoT protocol on port 853 to retrieve real IP addresses, hiding communication patterns. To protect its data, Stack XOR, which the researchers were able to “break” through emulation, revealing multiple hidden C2 servers.
See also: Tsundere Botnet targets Windows users with gaming bait

Industrial-scale DDoS
Kimwolf's offensive power was clearly evident between November 19 and 22, when it issued 1.7 billion DDoS commands against targets worldwide. The botnet supports 13 different attack methods, including UDP floods, TCP SYN floods, and SSL socket attacks, giving its operators great flexibility.
What does this mean for the future of Android?
The Kimwolf case highlights a critical problem: the inadequate security and updating of many Android devices, especially those that are not considered “personal.” As the IoT ecosystem continues to expand, such botnets show how millions of seemingly innocent devices can be turned into tools for massive cyberattacks, threatening the stability of the internet itself.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
