Researchers at Lumen Technologies’ Black Lotus Labs shut down a major botnet operation by blocking more than 550 command servers since October 2025. They did this by cutting off communication between the control servers and millions of infected devices. By blocking these internet addresses, they stopped infected devices from receiving instructions and updates.
The Botnet Threat
The Aisuru/Kimwolf botnet is one of the largest ever seen. It mainly targets cheap Android TV streaming boxes that come with poor security settings. These devices have a remote access feature (called ADB) that’s left open on port 5555, letting hackers get in without any password.
The infections usually come from pre-installed software called ByteConnect or from apps downloaded from sketchy app stores. Once infected, the device becomes part of a network that connects to remote control servers. These hacked devices are then used for internet attacks and to secretly route traffic for paid proxy services. Because they use regular home internet addresses, the malicious activity looks like normal household internet use, making it hard to detect.
Scale and Money-Making
Research shows the botnet infected over two million devices worldwide. The operators make money by selling access to these devices as proxies, usually through one-time payments rather than monthly subscriptions. They advertised their services on a Discord server at resi[.]to and worked with a hosting company called Resi Rack LLC, which hosted many of the control servers.
Takedown Details and How the Botnet Evolved
Researchers mapped out the botnet’s control network and found clusters of servers where many connected to Resi Rack, that controlled the infected devices. In October 2025, they blocked one of the main control servers. The hackers quickly moved to a new server and pushed updates to their infected devices.
The botnet grows by automatically scanning the internet for vulnerable devices. It specifically looks for weak points in services like PYPROXY and tries to break into residential proxy networks. Once a device is infected, its internet address gets added to proxy rental marketplaces.
These rented proxy devices are then used to scan for more vulnerable devices like routers, smart home gadgets, or streaming boxes. This creates a cycle where compromised devices help find and infect new ones automatically.
Broader Threat Landscape
This disruption happened alongside similar findings about other botnets, including ones using hundreds of hacked Russian routers. These cases show a growing trend: criminals are increasingly using regular home devices to hide their activities.
By hiding malicious operations within normal home internet traffic, attackers create a stable platform for stealing passwords, committing fraud, scraping websites, and launching other attacks. The growing size and complexity of these botnets shows the serious security risk from poorly secured home devices and the need for coordinated action to stop them.