Who is the Kimwolf Botmaster “Dort”?
2026-03-04T21:14:52Z•71d19028431b179a8fd67987f0d91f05b03c45ee9d1ce5ac88b1bc2b7ca703c0
Android TVBadbox 2.0DDoSDortI2PIoTKimwolfMFA bypassMicrosoft Patch TuesdayScattered Lapsus ShinyHuntersStarkillerbotmasterbotnetcredential theftdoxingextortionlocal network scanningphishingphishing-as-a-servicesupply-chainswattingvulnerability managementzero-day
What happened
Multiple KrebsOnSecurity pieces in early 2026 describe a large, active cybercrime ecosystem centered on the Kimwolf IoT botnet (over 2 million infected devices) that scans local networks, conducts massive DDoS attacks, relays abusive traffic, and has been used to compromise other botnets (e.g., Badbox 2.0). The Kimwolf operators (notably a handle “Dort”) have coordinated harassment, doxing, email flooding and even SWATing of researchers; Kimwolf has been leveraging anonymity networks such as I2P to resist takedown. Separately, a stealthy phishing-as-a-service called “Starkiller” proxies real,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 71d19028431b179a8fd67987f0d91f05b03c45ee9d1ce5ac88b1bc2b7ca703c0
- Enrichment time
- 2026-03-04T21:14:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.