Who is the Kimwolf Botmaster “Dort”?
2026-03-07T01:23:30Z•c9a2904d17a6a38ab3015c2aee8d07af26a211adf55400791b58035cc4d06a4b
AisuruAndroid TVBadbox 2.0DDoSDortI2PIoTKimwolfMFA-bypassMicrosoft Patch TuesdayScattered Lapsus ShinyHuntersStarkillerbotmasterbotnetcredential-relaydoxinglocal-network-scanningphishingphishing-as-a-serviceswattingvulnerabilityzero-day
What happened
Between January–February 2026 KrebsOnSecurity published a series of investigations describing a large, active IoT botnet (Kimwolf) and related threats. Kimwolf has infected more than 2 million devices—primarily unofficial Android TV streaming boxes—by exploiting a vulnerability that lets it scan and compromise devices on local networks. It has been used for massive DDoS attacks, to relay abusive traffic, to evade takedowns via I2P, and to compromise or claim compromise of other botnets (e.g., Badbox 2.0). The apparent Kimwolf operator known as “Dort” has coordinated harassment against security
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- c9a2904d17a6a38ab3015c2aee8d07af26a211adf55400791b58035cc4d06a4b
- Enrichment time
- 2026-03-07T01:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.