HomeSecurityKimwolf Botnet has infected 1.8 million Android devices

Kimwolf Botnet has infected 1.8 million Android devices

One of the largest and most sophisticated botnets ever recorded in the Android has begun to worry the global cybersecurity community. The malware, codenamed Kimwolf, is now considered one of the most serious threats, as it has managed to infect approximately 1.8 million Android devices worldwide.

Kimwolf Botnet

From smartphones to smart TVs

Kimwolf is not limited to classic mobile phones. Instead, it targets a wide range of Android-based devices, such as smart TVs, set-top boxes, tablets, and embedded systems. This makes it particularly dangerous, as many of these devices remain active 24/7 and often do not receive regular security updates.

See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet

The discovery of the botnet

Security researchers first discovered Kimwolf in October 2025, when a trusted community contributor provided an initial sample. What was particularly striking was that the malware communicated with a command and control (C2) domain, which at the time was ranked second globally in popularity according to Cloudflare statistics – a choice that helped the botnet “get lost” in the vast volume of legitimate traffic.

Kimwolf Botnet has infected 1.8 million Android devices

Global expansion without borders

The geographic reach of Kimwolf is impressive. Infected devices are found in 222 countries and regions , with the largest concentrations recorded in Brazil (14.63%) , India (12.71%) , and the United States (9.58%) . This distribution across different time zones makes it significantly more difficult for security analysts to continuously monitor and respond promptly .

A botnet designed for cyber warfare

According to analysts at Xlab Qianxin , Kimwolf is a highly sophisticated botnet, written using the Android NDK , which makes it highly performant and difficult to analyze. In addition to classic DDoS attacks, it also has proxy forwarding , reverse shell , and file management capabilities , turning each infected device into a fully controlled attack node.

See also: Aisuru botnet behind 29.7 Tbps DDoS attack

Advanced concealment techniques

One of the most concerning features of Kimwolf is its evasion techniques. The malware uses DNS over TLS (DoT) to communicate, bypassing traditional network surveillance systems. It also uses elliptic-curve-based digital signaturesto ensure that only authentic commands from C2 servers can be executed.

How it infects and remains on devices

The infection mechanism is based on an APK file, which decompresses and executes a native binary disguised as a legitimate system service . A Unix domain socket is then created with a name related to the botnet version to ensure that multiple instances are not running simultaneously.

Kimwolf decrypts embedded C2 domains and uses the DoT protocol on port 853 to retrieve real IP addresses, hiding communication patterns. To protect its data, Stack XOR, which the researchers were able to “break” through emulation, revealing multiple hidden C2 servers.

See also: Tsundere Botnet targets Windows users with gaming bait

Kimwolf Botnet has infected 1.8 million Android devices

Industrial-scale DDoS

Kimwolf's offensive power was clearly evident between November 19 and 22, when it issued 1.7 billion DDoS commands against targets worldwide. The botnet supports 13 different attack methods, including UDP floods, TCP SYN floods, and SSL socket attacks, giving its operators great flexibility.

What does this mean for the future of Android?

The Kimwolf case highlights a critical problem: the inadequate security and updating of many Android devices, especially those that are not considered “personal.” As the IoT ecosystem continues to expand, such botnets show how millions of seemingly innocent devices can be turned into tools for massive cyberattacks, threatening the stability of the internet itself.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS