In early 2026, researchers from KrebsOnSecurity exposed Kimwolf, a large-scale botnet that compromised more than two million devices by abusing unofficial Android TV streaming boxes. Investigators have since reconstructed the ecosystem of operators, proxy services, and hosting providers that enabled its growth and resilience.

Discovery and Early Attribution

Chinese security firm XLab published its detailed Kimwolf analysis on December 17, 2025. The malware coerces infected devices into launching DDoS attacks and relaying traffic for residential proxy networks. Kimwolf specifically targeted software pre-installed on over a thousand models of unauthorized Android TV boxes, quietly converting them into infrastructure for ad fraud, account takeovers, and large-scale data scraping.

XLab also confirmed Kimwolf’s connection to the earlier Aisuru botnet. While similarities in code had raised suspicions months earlier, definitive proof emerged on December 8, when both botnets were observed being distributed from the same IP address, 93.95.112.59.

Hosting and Proxy Enablement

That IP address was traced to Resi Rack LLC, a Utah-based company advertising itself as a game server host while also promoting residential proxy services on cybercrime forums. Although co-founder Cassidy Hales (“Shox”) claimed the company addressed the issue promptly after notification, independent timelines suggest Resi Rack infrastructure was involved weeks earlier.

Security researchers observed Kimwolf proxy traffic operating through multiple Resi Rack IP addresses as early as October 2025. A private Discord server, resi.to, became a coordination hub where participants shared IPs used to relay traffic from infected devices. Both Hales and his business partner were active in this community before abruptly shutting down static ISP proxy offerings following restrictive routing policy changes announced by major U.S. ISPs in early 2025.

Operators Behind the Botnet

The resi.to server was reportedly controlled by an individual known as “Dort,” believed to be a Canadian resident running the Aisuru/Kimwolf operation alongside an associate called “Snow.” After public reporting on Kimwolf, the Discord server was wiped and deleted, with members migrating to Telegram channels where they doxed researchers and complained about the difficulty of securing reliable bulletproof hosting.

Proxy Monetization Layer

Both Synthient and XLab found that Kimwolf deployed multiple components to transform infected devices into proxy endpoints. A key element was ByteConnect, an SDK distributed by Plainproxies and marketed as an ethical app monetization tool. In practice, researchers observed the SDK facilitating large volumes of credential-stuffing and abusive traffic.

Plainproxies leadership overlaps with other infrastructure repeatedly linked to DDoS activity and large-scale Internet scanning. Despite public disclosures, the ByteConnect SDK remains active on Kimwolf-infected systems.

Another proxy reseller, Maskify, was identified as a major outlet for Kimwolf-derived bandwidth, advertising millions of residential IPs at prices far below legitimate market rates. Researchers note that such pricing strongly indicates illicit sourcing and deliberate exploitation of compromised devices.

Retaliation and Infrastructure Hardening

Following exposure, Kimwolf operators retaliated with DDoS attacks and harassment campaigns. They also migrated command-and-control discovery to the Ethereum Name Service, embedding server locations in blockchain text records. This allows rapid recovery from takedowns by simply updating on-chain records, which infected devices automatically re-query.

Researchers observed ENS records containing taunts and explicit instructions advising that compromised TV boxes be destroyed if detected.

Ongoing Risk

Kimwolf continues to threaten a broad range of Android TV devices that lack even minimal security controls. Some ship with proxy malware already embedded, and in many cases a single network packet can grant administrative access.

Both XLab and Synthient strongly recommend disconnecting affected TV boxes immediately. The operational risk and downstream abuse enabled by these devices far outweigh any perceived benefit of keeping them online.