Who is the Kimwolf Botmaster “Dort”?
2026-03-08T01:23:29Z•b7f19b36ffaed3b5ad5d44ffca93283cd4ba24c5e5868be9aa28fa30fdabab7d
aisuruandroid-tvbadbox-2.0botnetcredential-theftddosdort (botmaster)doxxingi2piotkimwolfmfa-bypasspatch-tuesdayphishing-as-a-servicescattered-lapsus-shinyhuntersstarkillerswattingvulnerability-disclosurezero-day
What happened
A series of KrebsOnSecurity reports from Jan–Feb 2026 detail the rapidly spreading Kimwolf IoT botnet ( >2 million devices) that scans local networks to infect devices, conducts massive DDoS and abusive-relay traffic, and is leveraging anonymity networks (I2P) to evade takedowns. The alleged Kimwolf operator “Dort” has been linked to coordinated doxing, email-flooding, harassment and even a SWATing incident against a security researcher. Related coverage highlights ecosystem impacts (compromise of Badbox 2.0 Android TV devices, links to Aisuru), a stealthy “Starkiller” phishing-as-a-service (a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- b7f19b36ffaed3b5ad5d44ffca93283cd4ba24c5e5868be9aa28fa30fdabab7d
- Enrichment time
- 2026-03-08T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.