Who is the Kimwolf Botmaster “Dort”?
2026-03-04T21:16:49Z•d6c40be219de07dd02d580a8c38f20b64b8bfa19bcb0db9aced306575de98673
AisuruAndroid TVBadboxDDoSDort (actor)I2PIoTKimwolfMFA bypassMicrosoft patchesPatch TuesdayScattered Lapsus ShinyHuntersStarkilleranonymity networkbotnetcredential theftdoxingphishingphishing-as-a-serviceproxy phishingsupply chainswattingzero-day
What happened
Between January–February 2026 KrebsOnSecurity published a series of investigations exposing the Kimwolf IoT botnet (now >2 million infected devices) and related activity: mass compromise of unofficial Android TV streaming boxes, propagation into corporate and government networks, takeover/interaction with the Badbox 2.0 botnet, and use of I2P to evade takedowns. The Kimwolf operators (handle “Dort”) have coordinated large-scale DDoS, doxing, email‑flooding and harassment campaigns (including swatting), and have leaked clues about affiliate beneficiaries. Separately, researchers identified a “h
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- d6c40be219de07dd02d580a8c38f20b64b8bfa19bcb0db9aced306575de98673
- Enrichment time
- 2026-03-04T21:16:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.