Who is the Kimwolf Botmaster “Dort”?

2026-03-04T21:17:05Zfa5412fa42d1bf2b163198cfd65090f2f8cad2a03be8a81cf0fd8c14dbaada41
android-tvbadbox-2.0botnetddosdortdoxingi2piot-botnetkimwolfmfa-bypassmicrosoft-patch-tuesdaynetwork-scanningphishingphishing-as-a-servicestarkillerswattingvulnerability-exploitationzero-day

What happened

Between January–February 2026 KrebsOnSecurity documented an emergent, large-scale IoT botnet family dubbed “Kimwolf” (reported at >2 million infected devices) that exploits vulnerabilities in unofficial Android TV streaming boxes and local networks to scan and spread, and that has been used for massive DDoS, doxing, email-flooding and even to trigger SWAT responses. The Kimwolf operators (using the handle “Dort”) have been linked to disruption of the I2P anonymity network and to claims of compromising the Badbox 2.0 control panel. Separately, a new phishing-as-a-service called “Starkiller” was

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
fa5412fa42d1bf2b163198cfd65090f2f8cad2a03be8a81cf0fd8c14dbaada41
Enrichment time
2026-03-04T21:17:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.