Who is the Kimwolf Botmaster “Dort”?
2026-03-04T21:13:09Z•2d8978fb94597f4ac3b0c53f5e743c90f59b0db7345cd30b92b6a6e6d599e7c3
AisuruAndroid TVBadbox 2.0DDoSI2P disruptionIoT botnetKimwolfMFA bypassMFA relayMicrosoft updatesPatch TuesdayScattered Lapsus ShinyHuntersStarkilleractive exploitationbotnet takeovercorporate/government impactcredential theftdoxingphishing-as-a-serviceproxy phishingsupply-chain compromiseswattingzero-day
What happened
KrebsOnSecurity (Jan–Feb 2026) published a series of stories documenting the rapid rise and abuse of the Kimwolf IoT botnet (reported >2 million infected devices) used for large-scale DDoS, network scanning and relaying abusive traffic, including disruption of the I2P anonymity network. Reporting covers alleged operator activity (handle “Dort”) including coordinated doxing, email-flooding and SWATing of researchers, claims of compromising the Badbox 2.0 control panel, and links to beneficiaries of Kimwolf/Aisuru activity. Separately, researchers disclosed a stealthy phishing-as-a-service (“St
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 2d8978fb94597f4ac3b0c53f5e743c90f59b0db7345cd30b92b6a6e6d599e7c3
- Enrichment time
- 2026-03-04T21:13:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.