Since October 2022, the Lumen Technologies threat intelligence group, Black Lotus Labs, has effectively taken down approximately 550 Command-and-Control (C2) Servers belonging to the international AISURU/Kimwolf BotNet.
Within a few months, AISURU and its Android-based counterpart, Kimwolf, have become among the largest active botnet networks capable of conducting Distributed Denial of Service (DDoS) Attacks and monetizing infected consumer devices through the use of residential proxies.
Kimwolf's BotNet Construction Methodology
The Kimwolf botnet is primarily built off of noncompliant Android TV/IPTV Streaming Devices via taking advantage of open-source Android Debug Bridge (ADB) Services. In previous independent research completed by QiAnXin XLab, it was found that the malicious code being used converts non-compliant Android devices to Residential Proxy Nodes by utilizing a software development kit (SDK) called, ByteConnect, either directly or through previously installed suspicious applications.
Due to this method, it is estimated that over 2 million Android Devices have become infected with attackers utilizing the Residential Proxy Networks to provide further access to additional TV/IPTV streaming boxes/home systems.
A follow-up report from Synthient documented that Kimwolf botnet Operators are now actively offering for sale product Proxy Bandwidth for the compromised devices in return for advance payments.
How Kimwolf is Creating Its Botnet
Kimwolf mostly preys upon unauthorized Android television set-top streaming devices that have had their Android Debug Bridge (ADB) service exposed. In a previous report published by QiAnXin XLab indicated that the malware used transforms the targeted/infested device into a Residential Proxy Node by dropping an SDK called ByteConnect directly onto the device or via some type of pre-loaded or bundled applications.
Currently, there are an estimated 2 million infected Android devices, and the attackers utilize the residential proxy network to create tunnels into more television set-top boxes and home appliances.
According to Synthient, in a follow-up report, the Kimwolf operators are actively selling the proxy bandwidth derived from these devices and charging users a fee for the downloads.
C2 Infrastructure and Proxy Abuse
In September 2025, Black Lotus Labs analyzed the Command-and-Control Infrastructure (C2) of the Aleksandra ISURU malware after finding residential SSH connections from Canadian IPs connecting to proxy infrastructure on potentially malicious domains that are associated with the (14emeliaterracewestroxburyma02132.su) domain at the time.
One of these domains briefly ranked in the May 2025 Cloudflare Top-100 lists of domains before dropping off that list and being removed from circulation due to its misuse.
Finding the second command-and-control domain in early October 2025 that led investigators to Resi Rack, L.L.C. a U.S. based company that promotes itself as a premier Game Server Host. This finding is particularly significant due to previous reporting by journalist Brian Krebs, which identified the founders of Resi Rack as having previously sold access to residential proxy services powered by botnets via a now non-working Discord Server, [resi.to](resi.to).
Rapid Rise in Botnets (Explosive Growth of Botnets)
Black Lotus Labs Learned That Between October 20, 2025 And The End Of October, There Was A Influx Of 300 Percent Of Newly Infected Devices Caught In The Kimwolf Botnet, With The C2 Infrastructure Of This Group Being Found To Grew By About 800,000 Devices In Just A 2 Week Time Period With The Majority Of These Devices Being Sold Via Only One Residential Proxy Service Provider
In Further Analysis, Black Lotus Labs Found That Kimwolf’s Command And Control Infrastructure Was Scanning The List Of Proxy Servers For Vulnerabilities (Such As On PYPROXY) That Allowed Them To Take Over And Access The Internal Networks Of People’s Neighbourhoods (Through Exploitable Vulnerabilities). Once Inside The Home Network, The Kimwolf Malware Spread Laterally By Scanning Every Connected Device For ADB Enabled Capability.
By Doing So, They Are Able To Create Rentable Residential Proxies That Can Blend Their Malicious Traffic With Normal Internet Traffic.
Why Are Residential Proxies A Threat?
By Using The IP address Of Someone’s Home/Residence, The Attackers Have A Significant Advantage Because Traffic Generated From The Devices Of A Compromised Home User Is Often Completely Obscured And Bypasses Reputation-Based Defenses; Traffic That Comes From Data Centers And Hosting Facilities Will Not.
Black Lotus Labs Note, Even After Taking Down One Of Their Command & Control Servers, The Operators Were Able To Quickly Move To Another Place And Resume Hosting Malware Without Skipping A Beat, Indicating An Extreme Level Of Resilience And Maturity When It Came To Their Operational Capacities.
Broader Trend: Consumer Devices as Attack Infrastructure
Recent disclosures confirm that a group of Chawkr researchers has identified 832 compromised KeeneticOS routers in Russian Internet Service Providers, all of which had the same SSH fingerprint and configuration indicating that these routers had been exploited using an automated mass exploitation method.
Because the devices themselves appear to be legitimate, they allow attackers to perform multi-level intrusions, steal credentials, perform scans and abuse proxy services without being detected for the most part.
Chawkr stated, “As potential endpoints are mostly invisible to security tools, and their reputation for being clean enables bad traffic to blend into the noise of everyday consumer activity.”
Takeaways
The use of consumer devices at mass scale as "weapons" in an ongoing trend of weaponizing consumer devices has changed the landscape. The Kimwolf campaign uses the home as a part of the infrastructure (the default infrastructure in today’s pyramid scheme or pyramid style of attack) is in use as botnet, and proxy and DoS-for-hire services. We can effectively disrupt these C2 nodes, however the underlying infrastructure allows for quick reinfection to continue to occur.
Source: The Hacker News