Categories: Cyber Security News

Kimwolf Botnet Hacked 2 Million Devices and Turned Users’ Internet Connections into Proxy Nodes

A powerful new botnet called Kimwolf has infected more than two million devices worldwide, hijacking them to launch DDoS attacks, commit ad fraud, and secretly sell their bandwidth through residential proxy networks.
Sponsored

Security firm Synthient, which discovered the scale of the infection, says most compromised systems are Android TV boxes and digital photo frames sold by third-party merchants on platforms like Amazon, Walmart, and Newegg.

Synthient’s founder, Benjamin Brundage, revealed that Kimwolf spreads through a combination of pre-installed malware and a vulnerability in several residential proxy services.

These proxy networks are often marketed as legal tools for web scraping or anonymized browsing. However, many rely on unsafe devices or apps that silently convert users’ connections into proxy nodes rented out to others.

Brundage explained that Kimwolf attackers abused weak proxy configurations by altering DNS records to point to local IP addresses defined in [RFC 1918]. This trick allowed them to “tunnel” into private home networks hidden behind routers and firewalls, an area once thought safe.

Once inside, Kimwolf scanned for devices with Android Debug Bridge (ADB) enabled, which enabled unauthenticated root access for installing additional malware.

Exploiting Proxy Networks and Unsafe Devices

Synthient’s investigation linked most infections to IPIDEA, one of the world’s largest proxy providers, with over 100 million advertised endpoints. Researchers found that Kimwolf had leveraged IPIDEA’s network to rebuild itself even after takedowns.

Two-thirds of the affected IPIDEA proxies were unsecured Android devices, primarily those running unofficial firmware.

After being notified by Synthient in December 2025, IPIDEA confirmed a “legacy testing module” had allowed unintended access to local networks. The company said it has since blocked the unsafe paths and restricted DNS resolution for internal IP ranges.

Sponsored
Superbox media streaming boxes for sale on Walmart.com.

Researchers also found that infected Android TV boxes shipped from manufacturers with ADB mode turned on by default, effectively leaving them open to remote control. Devices such as the Superbox series and low-cost streaming hardware variants were among the most exploited.

Security firm XLab later confirmed Kimwolf’s global reach, showing infection clusters in India, Brazil, the United States, and Russia. The botnet can quickly reassemble after disruptions, aided by constantly changing IP addresses within residential networks.

Experts warn users to avoid cheap, no-name Android TV boxes and unverified app stores. Legitimate manufacturers disable debug features and provide security updates that counterfeit devices lack.

Synthient has launched an online checker at synthient.com/check that lets users check whether their IP addresses were recorded on Kimwolf-infected systems. Those with affected hardware are urged to disconnect and replace the devices immediately.

Krebsonsecurity Cybersecurity researchers agree: Kimwolf’s rise proves that home networks are no longer safe by default, and exposing insecure IoT devices can turn any user’s connection into a cybercriminal’s tool.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post Kimwolf Botnet Hacked 2 Million Devices and Turned Users’ Internet Connections into Proxy Nodes appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

You could be an influencer without even realizing it

A similar AI shopping feature on TikTok. | The Verge In late February, Puck reported…

17 seconds ago

Today’s Best Deals: Astro Bot, MEGA Beatles Building Set, Hell Is Us for Xbox Series X, and More

There are plenty of deals you’ll want to grab today. If you weren’t able to…

24 minutes ago

Capcom Hid an Enormous Secret About Leon S. Kennedy That You’ll Only Realize After Resident Evil Requiem’s Credits Roll

We may now know the solution to Capcom's devious Resident Evil Requiem Final Puzzle, but…

24 minutes ago

Pokémon TCG: Perfect Order Elite Trainer Boxes Market Price Crashes After Massive Target Restock

Pokémon TCG's next Mega Evolution expansion, Perfect Order, is set to release on March 27.…

25 minutes ago

Jim Carrey Is Not a Clone, Insists Awards Official

If you’re fairly online, like we are, you probably heard about the viral rumor that…

25 minutes ago

APT28 Exploits MSHTML Zero-Day Ahead of February 2026 Patch Tuesday

Microsoft’s February 2026 Patch Tuesday fixed 59 flaws, but CVE-2026-21513 in the MSHTML framework stole…

53 minutes ago

This website uses cookies.