Security researchers have exposed a global botnet operation believed to have compromised over two million devices across the Android ecosystem in the last six months.
First emerging in August, cybersecurity firm Synthient has tracked the rapid expansion of the Kimwolf botnet as it aggressively targets Android devices and hijacks TV streaming boxes to harvest large pools of IP addresses.
Worryingly, the researchers discovered that the most targeted devices, often cheap TV boxes or Android‑based gadgets, are being shipped with risky software or even malware pre‑installed that provide insecure connections to residential networks, making devices easy for attackers to find.
The study found that 67% of all Android devices infected were unauthenticated, leaving them vulnerable to remote code execution the moment they appeared online.
“Once part of the residential proxy pool, Kimwolf will have scanned and exploited the device within minutes,” warned Synthient.
A variant of the notorious Aisuru Botnet, Synthient said that Kimwolf poses a “significant threat”, with threat actors actively using it to hammer organisations with huge waves of DDoS attacks, which data from Cloudflare shows have reached a record-breaking 29.7 Terabits per second.
Hundreds of thousands of infected devices have surfaced across countries like Vietnam, Brazil, India, and Saudi Arabia, with Synthient recording around 12 million unique IP addresses associated with the Kimwolf network every week, allowing attackers to cycle through a huge bank of home internet connections.
According to Synthient, those orchestrating these attacks have been observed monetising the botnet through app installs, selling residential proxy bandwidth, and selling its DDoS functionality.
Taking advantage of the flood of low-cost and unofficial Android devices available through third-party resellers, the group behind Kimwolf saw early, widespread adoption by offering access to its network of hacked IP addresses for as little as 20 cents per gigabyte, far below normal market rates.
“This approach likely helped fuel early development, with associated members spending earnings on infrastructure and outsourced development tasks,” said Synthient, adding that resellers “know precisely what they are selling” as proxies at such low prices are not ethically sourced.
Recommended reading
- DDoS Attacks Surge 2,844% in Conflict Zones, Report Claims
- Hackers Unleash ‘Company Killing’ DDoS Attack
- Record 7.3 Tbps DDoS Attack Blocked
Since Kimwolf depends on residential internet connections to infect devices, researchers recommended that providers block high-risk ports and restrict access to local networks, as well as wipe or destroy infected TV boxes.
Organisations at risk are encouraged to audit their network traffic and hardware for signs of infection, avoid placing potentially vulnerable devices, specifically TV boxes, on networks, and verify IP addresses to ensure they are not unknowingly running proxy software.
“The botnet’s unprecedented growth to over 2 million devices is not just a failure of individual device security but a systemic vulnerability within the residential proxy supply chain,” the cyber firm concluded.
“As long as demand for low-cost residential bandwidth continues to grow, the risk to organisations and individuals will remain high.”





