Kimwolf Botnet Hacked 2 Million Devices and Turned User’s Internet Connection as Proxy Node
The Kimwolf malware has compromised over 2 million devices globally, converting them into unauthorized proxy servers. This botnet is being leveraged for online fraud, cyberattacks, and data theft.
The Kimwolf malware has compromised over 2 million devices globally, converting them into unauthorized proxy servers. This botnet is being leveraged for online fraud, cyberattacks, and data theft.
Researchers identified this threat in late 2025, noting its sophisticated exploitation of vulnerabilities in popular proxy networks. The malware primarily targets low-cost Android TV boxes and digital photo frames, many of which are pre-configured with insecure settings.
Benjamin Brundage, a cybersecurity researcher, discovered that the malware exploits weaknesses in residential proxy services, allowing unauthorized access to home networks through compromised devices. The largest proxy network affected, IPIDEA, had a significant security flaw that criminals exploited to implant malware.
The attack method involves exploiting devices with Android Debug Bridge enabled, providing attackers with superuser access through commands such as “adb connect [device-ip]:5555.” Once access is gained, the malware is delivered by directing systems to download it from a specific web address using a passphrase.
The Kimwolf malware has compromised over 2 million devices globally, converting them into unauthorized proxy servers.
Synthient data indicates that two-thirds of affected devices are Android TV boxes, with others including digital photo frames and mobile phones running concealed proxy applications. These infected devices are used for spam, advertising fraud, account takeovers, and distributed denial-of-service attacks.
Despite takedown attempts, the Kimwolf botnet rapidly recovers by utilizing new proxy endpoints from IPIDEA's vast pool of over 100 million residential proxy addresses. The botnet operators monetize their activities by selling app installations, renting bandwidth, and facilitating DDoS attacks.
This attack strategy is expected to proliferate as more cybercriminals exploit these vulnerabilities, making residential proxy networks key targets for large-scale compromises and network breaches.
Based on reporting by Cyber Security News.
