Who is the Kimwolf Botmaster “Dort”?
2026-03-04T21:15:33Z•83c38f2249f6580635f09362c7ac05fc576ed5403ebd53d8627793410ab33d6c
Android TVBadbox 2.0DDoSI2PIoTKimwolfMFA-bypassPatch TuesdayStarkillerbotmasterbotnetcredential-phishingdoxingphishing-as-a-serviceproxy-phishingswattingtakedown-evasionzero-day
What happened
KrebsOnSecurity coverage details a large, active IoT botnet cluster (Kimwolf) that has infected over two million devices, scans local networks to propagate, and is being used for massive DDoS, abuse-relay traffic and takedown-evasion (including leveraging I2P). The Kimwolf operators (handle “Dort”) have also conducted harassment campaigns—doxing, email floods and even causing a SWAT response—against researchers. Related reporting links Kimwolf to compromise of the Badbox 2.0 Android-TV ecosystem. Separately, a new phishing-as-a-service called “Starkiller” proxies real login pages and transparr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 83c38f2249f6580635f09362c7ac05fc576ed5403ebd53d8627793410ab33d6c
- Enrichment time
- 2026-03-04T21:15:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.