Who is the Kimwolf Botmaster “Dort”?
2026-03-04T21:12:34Z•132b7e45f076afec26709015d72cb130697e755638028d6eef97ab698c2cf929
aisurubadbox-2.0botmaster-dortcredential-relayddosdoxxingi2piot-botnetkimwolfmalwaremfa-bypassmicrosoftpatch-tuesdayphishing-as-a-servicescattered-lapsus-shinyhuntersstarkillerswattingvulnerability-managementzero-day
What happened
A series of KrebsOnSecurity reports detailing a major IoT threat landscape in early 2026: Kimwolf — a rapidly spreading IoT botnet (reported >2M devices) that scans local networks, powers massive DDoS, and uses I2P for C2 resilience — plus ties to Badbox 2.0 and Aisuru. The alleged Kimwolf operator (“Dort”) has coordinated harassment, doxing, email floods and even caused a SWAT incident. Separately, a stealthy phishing-as-a-service called “Starkiller” proxies real login pages and relays credentials and MFA codes to bypass take-downs and capture multi-factor authentication. Coverage also flags:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 132b7e45f076afec26709015d72cb130697e755638028d6eef97ab698c2cf929
- Enrichment time
- 2026-03-04T21:12:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.