Who is the Kimwolf Botmaster “Dort”?
2026-03-05T19:23:34Z•38766d90effc59787111d6e5b5d6183f5ae22d2460e0c9646dac7a98a331adb6
android-tvbadbox-2.0botnetcredential-theftddosdortdoxingi2piotkimwolfmass-compromisemfa-bypassmicrosoft-patch-tuesdayphishing-as-a-servicescattered-lapsus-shinyhuntersstarkillersupply-chainswattingzero-day
What happened
A series of KrebsOnSecurity reports in early 2026 describe the rise and operations of the Kimwolf IoT botnet (now >2 million infected devices), its use of mass-compromised Android TV streaming boxes and local network scanning to spread, and disruptive activities including large-scale DDoS, relayed abusive traffic, doxing, email-flooding and even swatting against researchers. Kimwolf operators (handle “Dort”) have leveraged I2P to evade takedowns and have boasted of compromising other botnets’ control panels (Badbox 2.0). Separately, a new phishing-as-a-service called “Starkiller” proxies real,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 38766d90effc59787111d6e5b5d6183f5ae22d2460e0c9646dac7a98a331adb6
- Enrichment time
- 2026-03-05T19:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.