An emerging IoT botnet designated Kimwolf has compromised more than 2 million devices globally, conscripting them into large-scale distributed denial-of-service campaigns and channeling malicious traffic across the internet. The threat poses particular concern to enterprises because of its capacity to probe local networks attached to infected systems and propagate to additional IoT devices. Recent findings indicate the botnet has established a troubling foothold within both government and corporate environments.
During late 2025, Kimwolf expanded its reach by manipulating residential proxy services into forwarding harmful instructions to devices connected to proxy endpoints' local networks. Residential proxies function as commercial services that mask and geographically route web traffic, with major providers enabling customers to channel connections through endpoints across virtually every nation and metropolitan area.
Proxy software that converts devices into relay nodes typically arrives bundled covertly within various mobile applications and games. Once installed, this software forces the device to transmit malicious and unwanted traffic, encompassing advertising fraud, credential compromise attempts, and large-scale data harvesting operations.
Kimwolf operators concentrated efforts against IPIDEA, a Chinese residential proxy provider operating millions of available endpoints weekly. The attackers identified a method to transmit malicious instructions through IPIDEA's infrastructure to internal networks, enabling them to systematically locate and compromise additional vulnerable devices on each endpoint's connected network.
The majority of devices compromised through Kimwolf's network scanning have been unofficial Android TV streaming devices. These systems typically run Android Open Source Project rather than certified Android TV OS, and vendors market them as platforms for accessing unlimited—effectively pirated—content from major streaming services for a single payment.
A significant portion of these streaming boxes arrive with residential proxy software pre-loaded. Additionally, they incorporate minimal security measures or authentication mechanisms: direct communication with the device enables straightforward malware deployment.
Though IPIDEA and comparable proxy operators have recently implemented defenses to prevent Kimwolf from reaching upstream into their infrastructure (with reported inconsistent effectiveness), the malware persists across millions of infected systems.

Given Kimwolf's connection to residential proxy networks and compromised Android TV devices, one might anticipate limited corporate network presence. Nevertheless, security vendor Infoblox reported that nearly 25 percent of its monitored customers registered queries to Kimwolf-associated domains beginning October 1, 2025, when the botnet initially emerged.
Infoblox's affected customers span multiple continents and sectors including education, healthcare, government, and financial services.
To be clear, this suggests that nearly 25% of customers had at least one device that was an endpoint in a residential proxy service targeted by Kimwolf operators. Such a device, maybe a phone or a laptop, was essentially co-opted by the threat actor to probe the local network for vulnerable devices. A query means a scan was made, not that new devices were compromised. Lateral movement would fail if there were no vulnerable devices to be found or if the DNS resolution was blocked.
Infoblox

Synthient, a firm specializing in proxy service monitoring, became the first organization to publicly detail Kimwolf's propagation mechanisms on January 2. The company's analysis revealed IPIDEA proxy endpoints present in substantial quantities at educational and governmental institutions internationally. Synthient documented a minimum of 33,000 affected IP addresses at universities and colleges, alongside approximately 8,000 IPIDEA proxies embedded within assorted U.S. and international government infrastructure.
During a January 16 webinar, analysts from Spur, another proxy tracking platform, examined IP addresses connected to IPIDEA and ten additional proxy services suspected of vulnerability to Kimwolf's methods. Spur's investigation uncovered residential proxies distributed across nearly 300 government-controlled networks, 318 utility sector organizations, 166 healthcare entities or medical facilities, and 141 banking and financial institutions.
I looked at the 298 [government] owned and operated [networks], and so many of them were DoD [U.S. Department of Defense], which is kind of terrifying that DoD has IPIDEA and these other proxy services located inside of it. I don't know how these enterprises have these networks set up. It could be that [infected devices] are segregated on the network, that even if you had local access it doesn't really mean much. However, it's something to be aware of. If a device goes in, anything that device has access to the proxy would have access to.
Riley Kilmer, Spur Co-Founder
Kilmer emphasized that Kimwolf illustrates how a single proxy infection can escalate into substantial organizational risk when unsecured devices operate within corporate perimeters. Proxy services may provide attackers with a straightforward mechanism for probing networked devices within target organizations.
If you know you have [proxy] infections that are located in a company, you can chose that [network] to come out of and then locally pivot. If you have an idea of where to start or look, now you have a foothold in a company or an enterprise based on just that.
Riley Kilmer
This article represents the third installment in coverage of the Kimwolf botnet. Forthcoming reporting will examine the numerous China-based individuals and organizations connected to Badbox 2.0, a designation encompassing numerous Android TV streaming box models that ship without meaningful security or authentication capabilities and with residential proxy malware pre-installed.
Source: Krebs on Security