Author Topic: Kimwolf botnet and unofficial Android TV boxes  (Read 638 times)

0 Members and 1 Guest are viewing this topic.

Online madiresTopic starter

  • Super Contributor
  • ***
  • Posts: 8988
  • Country: de
  • A qualified hobbyist ;)
Kimwolf botnet and unofficial Android TV boxes
« on: January 02, 2026, 06:32:16 pm »
The Kimwolf Botnet is Stalking Your Local Network - https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/

TL;DR:
- new botnet with around 2 million devices
- weakness of hidden proxy service enables access to local networks (often preinstalled on unofficial Android TV boxes)
- takeover of devices with Android Debug Bridge enabled (nearly all unofficial Android TV boxes)
 

Online iMo

  • Super Contributor
  • ***
  • Posts: 6705
  • Country: pw
Re: Kimwolf botnet and unofficial Android TV boxes
« Reply #1 on: January 02, 2026, 07:34:35 pm »
Quote
For example, opening a command prompt and typing “adb connect” along with a vulnerable device’s (local) IP address followed immediately by “:5555” will very quickly offer unrestricted “super user” administrative access.

Hopefully our Rigols are not infected..  :D
Readers discretion is advised..
 

Online madiresTopic starter

  • Super Contributor
  • ***
  • Posts: 8988
  • Country: de
  • A qualified hobbyist ;)
Re: Kimwolf botnet and unofficial Android TV boxes
« Reply #2 on: June 20, 2026, 04:10:36 pm »
Another botnet based on Android devices:
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm - https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/

And some numbers about Kimwolf from the recent NANOG 97:
-  The Kimwolf Aftershock: Residential Proxy Botnets One Year Later - https://nanog.org/events/nanog-97/content/5771/

A US residential proxy costs up to about US$ 95 for two weeks. It's a quite profitable business!
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf