Who is the Kimwolf Botmaster “Dort”?

2026-03-07T01:23:30Zc9a2904d17a6a38ab3015c2aee8d07af26a211adf55400791b58035cc4d06a4b
AisuruAndroid TVBadbox 2.0DDoSDortI2PIoTKimwolfMFA-bypassMicrosoft Patch TuesdayScattered Lapsus ShinyHuntersStarkillerbotmasterbotnetcredential-relaydoxinglocal-network-scanningphishingphishing-as-a-serviceswattingvulnerabilityzero-day

What happened

Between January–February 2026 KrebsOnSecurity published a series of investigations describing a large, active IoT botnet (Kimwolf) and related threats. Kimwolf has infected more than 2 million devices—primarily unofficial Android TV streaming boxes—by exploiting a vulnerability that lets it scan and compromise devices on local networks. It has been used for massive DDoS attacks, to relay abusive traffic, to evade takedowns via I2P, and to compromise or claim compromise of other botnets (e.g., Badbox 2.0). The apparent Kimwolf operator known as “Dort” has coordinated harassment against security

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
c9a2904d17a6a38ab3015c2aee8d07af26a211adf55400791b58035cc4d06a4b
Enrichment time
2026-03-07T01:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Who is the Kimwolf Botmaster “Dort”? · Baitaphish