Kimwolf Android Botnet is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 18, 2025; most recent activity January 5, 2026.
Kimwolf Android Botnet is a malware family that compromises Android devices by exploiting exposed Android Debug Bridge (ADB) endpoints and enrolling them into a distributed proxy network. It leverages these devices as residential proxies to route traffic, enabling large-scale, anonymous network activity. Its rapid growth to millions of devices makes it a significant threat to Android security and network integrity.
The Kimwolf malware has infected over 2 million devices globally, turning them into illegal proxy servers without user consent. This botnet is being utilized for online fraud, cyberattacks, and information theft,…
The Kimwolf botnet has compromised approximately 1.8 million Android devices worldwide, including smart TVs and tablets. Discovered by security researchers, this sophisticated malware represents a significant threat in…