HomeSecurityKimwolf botnet abuses home proxy networks

Kimwolf botnet abuses home proxy networks

One of the most alarming phenomena in the cybersecurity world has been developing almost silently in recent months. The Kimwolf botnet, an Android variant of the notorious malware Aisuru, has now infected more than two million devices, exploiting security vulnerabilities in home proxy networks and turning everyday Android devices into weapons of mass cyberattacks.

Kimwolf botnet proxy

From Aisuru to Kimwolf: A dangerous evolution

Aisuru is no stranger to the industry. The botnet has already been linked to the largest recorded DDoS attack in history, which reached 29.7 terabits per second, according to Cloudflare. The Kimwolf version brings this philosophy to the Android world, dramatically expanding its reach across smart TVs, TV boxes, and streaming devices.

See also: Exploiting critical vulnerability in old D-Link DSL routers

Researchers have observed increased activity since last August, with the botnet escalating its attacks over the past month, systematically scanning proxy networks for exposed Android Debug Bridge (ADB) services.

Android TVs in the spotlight

Kimwolf's main targets are Android TVs and streaming devices that allow access via ADB without sufficient authentication. Once a device is compromised, it joins the botnet and is used for multiple purposes: DDoS attacks, reselling access as a proxy, and generating revenue through mass app installs with the help of third-party SDKs, such as Plainproxies Byteconnect.

Kimwolf botnet abuses home proxy networks

Millions of devices, millions of IPs

According to Synthient, a company that specializes in detecting online threats and fraud, Kimwolf is approaching two million infected Android devices. The botnet generates about 12 million unique IP addresses every week, which makes it extremely difficult to detect and block. Most infections are found in Vietnam, Brazil, India and Saudi Arabia, while in many cases the devices appear to have already been “loaded” with suspicious proxy SDKs before they were even purchased.

See also: Hacker group compromises multiple FortiWeb devices

The abuse of home proxies

The rapid spread of the Kimwolf botnet is largely due to the abuse of home proxy networks. Some providers allow access to local IP addresses and ports, giving the malware the ability to communicate directly with devices on the same internal network.

Since mid-November 2025, researchers have detected mass scans for open ADB ports, such as 5555, 5858, 12108, and 3222. When ADB is exposed, it allows remote commands, application installation , and complete control of the device. Kimwolf payloads are delivered via tools such as netcat and telnet, executing scripts directly on the system.

““Pre-infected” devices and serious exposure rates

Synthient found that in certain home proxy clusters, such as those associated with IPIDEA, up to 67% of Android devices lacked any form of authentication. In total, the researchers estimate that there are approximately six million vulnerable IPs worldwide. In many cases, these devices appear to have been shipped “pre-infected” by proxy providers, raising serious questions about the supply chain.

See also: New VVS Stealer targets Discord accounts via Python

Kimwolf botnet abuses home proxy networks

How to protect users

In response, Synthient has released an online scanning tool that allows users to check if any of their devices are part of the Kimwolf botnet. If an infection is detected, experts recommend radical solutions, such as completely deleting or even destroying the infected Android TV, as a simple reset is often not enough.

The general recommendation is clear: avoid cheap, unknown-origin Android TV devices and prefer certified products with Google Play Protect from trusted manufacturers (e.g. Google's Chromecast, NVIDIA Shield TV and Xiaomi Mi TV Box). In a world where even the TV can become a tool for cyberattack, security is no longer a luxury, but a necessity.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS