Who is the Kimwolf Botmaster “Dort”?

2026-03-08T07:23:28Z0daa6ec909d01a1081d91012de633d7fddeb0aecf1bbe8b2d19d48e8e0b9f997
DDoSaisuruandroid tvbadbox 2.0botnetcredential relaydoxingi2piot botnetkimwolfmfa bypassmicrosoft zero-daypatch-tuesdayphishing-as-a-servicescattered lapsus shinyhuntersstarkillerswattingthreat-actor Dort

What happened

Collection of KrebsOnSecurity reports (Jan–Feb 2026) detailing the rise and activity of the Kimwolf IoT botnet (now >2 million infected devices) and related threats. Kimwolf mass‑compromises unofficial Android TV boxes, scans local networks to propagate, is used for large DDoS campaigns, doxing, email‑flooding and even swatting, and has been leveraged to disrupt the I2P anonymity network and to seize control of other botnets (e.g., Badbox 2.0). A new phishing‑as‑a‑service called “Starkiller” acts as a live proxy/relay of legitimate login pages to capture credentials and MFA codes (MFA bypass).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
0daa6ec909d01a1081d91012de633d7fddeb0aecf1bbe8b2d19d48e8e0b9f997
Enrichment time
2026-03-08T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Who is the Kimwolf Botmaster “Dort”? · Baitaphish