In late 2025 and early 2026, analysts recorded rapid growth of the Kimwolf botnet, which has already infected more than 2 million Android devices. According to the company Synthient, the network has become one of the largest of its kind, Anti-Malware reports.
Features and capabilities of KimwolfThe key feature of the botnet is the use of residential proxies. Infected devices disguise malicious traffic as ordinary user traffic, making detection and blocking much more difficult.
The botnet is monetized in several ways:
selling mobile app installs renting out residential proxy traffic carrying out DDoS attacks on demandEach week, Kimwolf operates around 12 million unique IP addresses, indicating industrial scale and steady commercial demand.
Kimwolf is an Android version of the older AISURU botnet. Specialists from QiAnXin XLab first described it in late 2025. There are reasons to believe it was behind a series of record breaking DDoS attacks last year.
Geography and infection vectorsThe highest number of infections has been recorded in Vietnam, Brazil, India, and Saudi Arabia.
The main entry point is an open Android Debug Bridge without authentication. More than 67 percent of infected devices had unsecured ADB access. Attacks are carried out through residential proxy infrastructure, after which the malware is installed directly.
Devices at highest risk are unofficial Android TV boxes and smart TVs. They are often shipped with questionable SDKs or preinstalled third party software, which significantly simplifies infection.
Why this is dangerousExperts describe the situation as unprecedented. The botnet is not only massive but is also increasingly converging with legitimate proxy service providers. This blurs the line between cybercrime and conventional business, making countermeasures much more difficult.
Infected devices become part of an infrastructure for attacks, fraud, and bypassing restrictions without the owners’ knowledge.
How to protect yourself Disable ADB in developer settings if it is enabled Avoid suspiciously cheap TV boxes with unknown software Install system updates and use antivirus software Avoid installing apps from untrusted sources In briefThe Kimwolf botnet infected more than 2 million Android devices in a single month, mainly through open ADB access. It disguises itself as residential traffic and is used for DDoS attacks, fraud, and proxy rental. Budget TV boxes and smart TVs are particularly at risk. The scale of the network, around 12 million IP addresses weekly, makes it one of the largest threats of 2026. The main protection measures are disabling debugging features and being cautious when choosing devices.
Follow NEWS.am Tech on Facebook and Twitter