Who is the Kimwolf Botmaster “Dort”?

2026-03-04T21:14:52Z71d19028431b179a8fd67987f0d91f05b03c45ee9d1ce5ac88b1bc2b7ca703c0
Android TVBadbox 2.0DDoSDortI2PIoTKimwolfMFA bypassMicrosoft Patch TuesdayScattered Lapsus ShinyHuntersStarkillerbotmasterbotnetcredential theftdoxingextortionlocal network scanningphishingphishing-as-a-servicesupply-chainswattingvulnerability managementzero-day

What happened

Multiple KrebsOnSecurity pieces in early 2026 describe a large, active cybercrime ecosystem centered on the Kimwolf IoT botnet (over 2 million infected devices) that scans local networks, conducts massive DDoS attacks, relays abusive traffic, and has been used to compromise other botnets (e.g., Badbox 2.0). The Kimwolf operators (notably a handle “Dort”) have coordinated harassment, doxing, email flooding and even SWATing of researchers; Kimwolf has been leveraging anonymity networks such as I2P to resist takedown. Separately, a stealthy phishing-as-a-service called “Starkiller” proxies real,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
71d19028431b179a8fd67987f0d91f05b03c45ee9d1ce5ac88b1bc2b7ca703c0
Enrichment time
2026-03-04T21:14:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Who is the Kimwolf Botmaster “Dort”? · Baitaphish