Back Dublinlive.Ie 'Dodgy box' warning as Kimwolf malware 'botnet' infects up to 2 million devices
Millions of television boxes and similar devices could now be compromised by what experts called the most severe threat to global internet security in years, the 'Kimwolf' botnet.
In recent months, cybersecurity specialists have been tracking the rapid expansion of this new 'botnet,' a worldwide network of private computers and devices infected with malicious software now under the remote control of criminal syndicates. These gangs use off-brand TV boxes as Trojan Horses, smuggling pre-installed malware into the devices and networks of unsuspecting purchasers.
Available through Amazon and a host of other online retailers, these devices come under an array of unbranded models and makes. However, they carry a hidden price tag: the potential pre-installed malware that can infect anyone who connects them to their devices and networks.
Experts say that the dodgy box purchased to illicitly stream Apple TV or Sky Sports could be a spy in your living room, taking your sensitive data and infecting other devices globally. It's estimated that 400,000 Irish households now possess 'dodgy boxes.'
These compromised devices can both transmit sensitive information from that device and spread the infection to other devices. The infected devices then join the 'botnet' as the malware expands exponentially.
These TV boxes are being exploited by criminal syndicates primarily based in Russia and Asia, with the associated fraud estimated to be worth billions of dollars. These gangs can rake in the cash by leasing out the devices and bandwidth they've seized control of to other entities.
Using a concealed tool known as Byteconnect SDK, they can covertly install apps on our devices, earning a referral fee for each one without the owner's knowledge. They can also run a DDoS-for-hire service, leasing out their entire 2-million-device army to other criminals aiming to disable a major website or network.
These are large-scale assaults on websites and information systems intended to incapacitate them. They're akin to the attack on Ireland's Health Service Executive (HSE) on May 14th 2021, a ransomware cyberattack that led to a nationwide shutdown of its IT systems for several months, believed to have been masterminded by a Russian-based criminal network.
The latest significant botnet worry, known as 'Kimwolf', employs what are known as residential proxy networks. These are used by individuals seeking to anonymise and localise their web traffic to a specific region, thereby circumventing firewalls and other safeguards.
The Kimwolf malware not only forces compromised systems to further spread malicious and abusive traffic - such as ad fraud, account takeover attempts and mass 'content scraping' - but also utilises the internet to launch distributed denial-of-service (DDoS) attacks, reports Cork Beo .
The malware that commandeers devices is often concealed within dubious mobile apps and games. However, the primary distribution methods is through dodgy boxes.
For those seeking more information on how to safeguard themselves or report suspected fraud, Ireland's National Cybersecurity Centre offers a wealth of online resources.
Join our Dublin Live breaking news service on WhatsApp. Click this link to receive your daily dose of Dublin Live content. We also treat our community members to special offers, promotions, and adverts from us and our partners. If you don’t like our community, you can check out any time you like. If you’re curious, you can read our Privacy Notice .
For all the latest news from Dublin and surrounding areas visit our homepage .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
