Who is the Kimwolf Botmaster “Dort”?
2026-03-04T21:17:05Z•fa5412fa42d1bf2b163198cfd65090f2f8cad2a03be8a81cf0fd8c14dbaada41
android-tvbadbox-2.0botnetddosdortdoxingi2piot-botnetkimwolfmfa-bypassmicrosoft-patch-tuesdaynetwork-scanningphishingphishing-as-a-servicestarkillerswattingvulnerability-exploitationzero-day
What happened
Between January–February 2026 KrebsOnSecurity documented an emergent, large-scale IoT botnet family dubbed “Kimwolf” (reported at >2 million infected devices) that exploits vulnerabilities in unofficial Android TV streaming boxes and local networks to scan and spread, and that has been used for massive DDoS, doxing, email-flooding and even to trigger SWAT responses. The Kimwolf operators (using the handle “Dort”) have been linked to disruption of the I2P anonymity network and to claims of compromising the Badbox 2.0 control panel. Separately, a new phishing-as-a-service called “Starkiller” was
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- fa5412fa42d1bf2b163198cfd65090f2f8cad2a03be8a81cf0fd8c14dbaada41
- Enrichment time
- 2026-03-04T21:17:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.