Who is the Kimwolf Botmaster “Dort”?
2026-03-08T07:23:28Z•0daa6ec909d01a1081d91012de633d7fddeb0aecf1bbe8b2d19d48e8e0b9f997
DDoSaisuruandroid tvbadbox 2.0botnetcredential relaydoxingi2piot botnetkimwolfmfa bypassmicrosoft zero-daypatch-tuesdayphishing-as-a-servicescattered lapsus shinyhuntersstarkillerswattingthreat-actor Dort
What happened
Collection of KrebsOnSecurity reports (Jan–Feb 2026) detailing the rise and activity of the Kimwolf IoT botnet (now >2 million infected devices) and related threats. Kimwolf mass‑compromises unofficial Android TV boxes, scans local networks to propagate, is used for large DDoS campaigns, doxing, email‑flooding and even swatting, and has been leveraged to disrupt the I2P anonymity network and to seize control of other botnets (e.g., Badbox 2.0). A new phishing‑as‑a‑service called “Starkiller” acts as a live proxy/relay of legitimate login pages to capture credentials and MFA codes (MFA bypass).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 0daa6ec909d01a1081d91012de633d7fddeb0aecf1bbe8b2d19d48e8e0b9f997
- Enrichment time
- 2026-03-08T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.