Who is the Kimwolf Botmaster “Dort”?

2026-03-04T21:16:49Zd6c40be219de07dd02d580a8c38f20b64b8bfa19bcb0db9aced306575de98673
AisuruAndroid TVBadboxDDoSDort (actor)I2PIoTKimwolfMFA bypassMicrosoft patchesPatch TuesdayScattered Lapsus ShinyHuntersStarkilleranonymity networkbotnetcredential theftdoxingphishingphishing-as-a-serviceproxy phishingsupply chainswattingzero-day

What happened

Between January–February 2026 KrebsOnSecurity published a series of investigations exposing the Kimwolf IoT botnet (now >2 million infected devices) and related activity: mass compromise of unofficial Android TV streaming boxes, propagation into corporate and government networks, takeover/interaction with the Badbox 2.0 botnet, and use of I2P to evade takedowns. The Kimwolf operators (handle “Dort”) have coordinated large-scale DDoS, doxing, email‑flooding and harassment campaigns (including swatting), and have leaked clues about affiliate beneficiaries. Separately, researchers identified a “h

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
d6c40be219de07dd02d580a8c38f20b64b8bfa19bcb0db9aced306575de98673
Enrichment time
2026-03-04T21:16:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.