Lumen Technologies' Black Lotus Labs team reported that it has blocked traffic to over 550 command and control (C2) nodes connected to the AISURU/Kimwolf botnet since early October 2025.
See also: Kimwolf botnet abuses home proxy networks

AISURU and its Android counterpart, Kimwolf, have evolved into significant botnets capable of directing compromised devices to participate in distributed denial-of-service (DDoS) attacks and transporting malicious traffic for home proxy services.
Details about Kimwolf emerged last month when QiAnXin XLab published an extensive analysis of the malware, which turns compromised devices—primarily unauthorized Android TV streaming devices—into home intermediaries by delivering a software development kit (SDK) called ByteConnect, either directly or through questionable pre-installed apps.
As a result, the botnet has expanded to infect over 2 million Android devices with an exposed Android Debug Bridge (ADB) through infiltration of home proxy networks, allowing threat actors to compromise a wide range of set-top boxes.
A subsequent report from Synthient revealed that Kimwolf perpetrators were attempting to offload the bandwidth of intermediaries in exchange for immediate payment.
Black Lotus Labs identified a cluster of residential SSH connections originating from multiple Canadian IP addresses in September 2025 based on its analysis of the Aisuru C2 backend at 65.108.5[.]46. The IP addresses were using SSH to access 194.46.59[.]169, which is associated with proxy-sdk.14emeliaterracewestroxburyma02132[.]su.
See also: RondoDox Botnet Exploits React2Shell Vulnerability

Significantly, this subdomain surpassed Google in Cloudflare's top 100 domains list in November 2025, which led the web infrastructure company to remove it from the list.
In early October 2025, the cybersecurity firm detected another C2 domain—greatfirewallisacensorshiptool.14emeliaterracewestroxburyma02132[.]su—at the IP address 104.171.170[.]21, which belongs to Utah-based hosting provider Resi Rack LLC , which advertises itself as a “Premium Game Server Hosting Provider.”
This link is significant, as a recent report by independent security journalist Brian Krebs revealed that individuals behind various botnet-based mediation services were selling their services on a Discord server called resi[.]to. This included the co-founders of Resi Rack, who had been actively involved in selling mediation services via Discord for nearly two years.
Kimwolf's C2 architecture was then found scanning PYPROXY and other services for vulnerable devices between October 20, 2025, and November 6, 2025—a behavior attributed to the botnet exploiting a security vulnerability in multiple proxy services that allowed it to interact with devices on the internal networks of home proxy endpoints and install malware.
This process turns the device into a home proxy node, causing its public IP address (assigned by the ISP) to be registered for rent on a home proxy website. The threat actors behind these botnets then rent access to the infected node and use it to scan the local network for ADB-enabled devices for further propagation.
See also: Kimwolf Botnet has infected 1.8 million Android devices

The revelation coincides with a report from Chawkr describing a sophisticated proxy network containing 832 compromised KeeneticOS operating through Russian ISPs, such as Net By Net Holding LLC and VladLink.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
