Operators of Kimwolf, a botnet affecting over 2 million devices, recently disclosed that they had gained entry to the administrative interface of Badbox 2.0, a large botnet originating from China that relies on malware bundled into Android TV streaming boxes. The FBI and Google have both indicated they are actively investigating those responsible for Badbox 2.0, and the Kimwolf operators' public disclosure may now provide crucial leads in identifying them.
Kimwolf itself has a documented history of employing aggressive distribution techniques, as covered in earlier reporting. The majority of systems compromised by Kimwolf are non-standard Android TV boxes marketed to consumers as providing access to unlimited pirated entertainment for a single upfront payment. According to previous investigations, the individuals managing Kimwolf operations have used the aliases "Dort" and "Snow."
A former associate of Dort and Snow furnished what they claimed was a screenshot captured from within the Badbox 2.0 control panel. The image displays seven authorized users, with one account standing out: "ABCD," which according to the source belongs to Dort and represents unauthorized access to the Badbox 2.0 system.
Badbox 2.0 has existed well before Kimwolf's emergence in October 2025. Google initiated a lawsuit in July 2025 against 25 unnamed defendants allegedly running Badbox 2.0, characterizing it as a network of more than ten million unauthorized Android streaming devices engaged in advertising fraud. Google noted that Badbox 2.0 compromises devices both before and after purchase, including through malicious applications distributed via unofficial app stores.
The FBI had previously issued a warning in June 2025 regarding cybercriminals exploiting home networks through devices infected with malware either before sale or during initial setup when downloading required applications containing backdoors. The FBI indicated that Badbox 2.0 emerged following the shutdown of the original Badbox campaign in 2024, which itself had been identified in 2023 as consisting primarily of compromised Android TV boxes infected with backdoor malware prior to consumer purchase.
Initial skepticism about whether Kimwolf's operators truly compromised Badbox 2.0 gave way to verification after examining the qq.com email addresses visible in the control panel screenshot.
Tracing the Infrastructure
The email address 34557257@qq.com, identified in the screenshot under the user "Chen," appears as a contact point for several China-based technology firms, including Beijing Hong Dake Wang Science & Technology Co Ltd., Beijing Hengchuang Vision Mobile Media Technology Co. Ltd., and Moxin Beijing Science and Technology Co. Ltd.
Beijing Hong Dake Wang Science operates the website asmeisvip[.]net, which was flagged in a March 2025 report by HUMAN Security as connected to Badbox 2.0 distribution and administration. The domain moyix[.]com, linked to Beijing Hengchuang Vision Mobile, was similarly identified.
Breach records from Constella Intelligence show that 34557257@qq.com was previously associated with the password "cdh76111." Cross-referencing this password revealed it had been used by two other email accounts: daihaic@gmail.com and cathead@gmail.com.
Constella identified that cathead@gmail.com created a jd.com account in 2021 under the name "陈代海" (Chen Daihai). Domain registration records from 2008 for moyix[.]com, according to DomainTools, list Chen Daihai as the registrant along with the email cathead@astrolink[.]cn. The domain astrolink[.]cn itself appeared in HUMAN Security's 2025 list of Badbox 2.0-associated domains.
DomainTools shows that cathead@astrolink[.]cn registered more than a dozen domains, including vmud[.]net, which HUMAN Security also tagged as part of the Badbox 2.0 infrastructure.
Identifying Additional Operators
An archived version of astrolink[.]cn from archive.org reveals the site belonged to Beijing Astrolink Wireless Digital Technology Co. Ltd., a mobile application development company. The archived contact page lists Chen Daihai as a member of the technology department, alongside Zhu Zhiyu, whose email was shown as xavier@astrolink[.]cn.

In the Badbox 2.0 control panel, the user "Mr.Zhu" employed the email xavierzhu@qq.com. Constella found this address registered a jd.com account under the name Zhu Zhiyu. A distinctive password associated with this account matches one used by xavierzhu@gmail.com, which DomainTools identifies as the original registrant of astrolink[.]cn.
The "admin" account in the Badbox 2.0 panel, created in November 2020, used the email 189308024@qq.com. DomainTools connects this address to 2022 registration records for guilincloud[.]cn under the name "Huang Guilin."
Constella linked 189308024@qq.com to the Chinese phone number 18681627767. The OSINT platform osint.industries found this number connected to a Microsoft profile established in 2014 under "Guilin Huang" (桂林 黄). Spycloud indicates the same phone number was used in 2017 to create a Weibo account with the username "h_guilin."

The remaining three control panel users and their associated qq.com addresses all traced back to individuals within China, though none appeared connected to the entities established by Chen Daihai and Zhu Zhiyu, nor to any corporate structures. None of these individuals provided responses to inquiries.
Implications of Unauthorized Access

The possibility that Kimwolf's operators possess direct access to Badbox 2.0's control infrastructure carries significant implications. Understanding the severity requires context on Kimwolf's propagation methods. The botnet's administrators discovered they could manipulate residential proxy services into forwarding malicious instructions to vulnerable devices within users' local networks.
Kimwolf targets primarily Internet of Things devices—particularly non-standard Android TV boxes and digital photo frames—that lack meaningful security measures or authentication protocols. Essentially, any entity capable of communicating with these devices can compromise them through a single command.
Research from Synthient, a residential proxy monitoring firm, alerted eleven residential proxy providers in January that their infrastructure was susceptible to misuse for local network reconnaissance and exploitation. Most of these providers subsequently implemented protections preventing customers from accessing the local networks connected to residential proxy endpoints, seemingly limiting Kimwolf's rapid expansion.
Yet according to the source who provided the Badbox 2.0 screenshot, Kimwolf's operators possessed a contingency: direct access to the Badbox 2.0 control infrastructure.
Dort has gotten unauthorized access. So, what happened is normal proxy providers patched this. But Badbox doesn't sell proxies by itself, so it's not patched. And as long as Dort has access to Badbox, they would be able to load the Kimwolf malware directly onto TV boxes associated with Badbox 2.0.
Source familiar with Kimwolf operations
The source indicated uncertainty regarding how Dort obtained access to the Badbox control panel. However, the unauthorized ABCD account is unlikely to remain functional for long: all qq.com email addresses listed in the control panel screenshot received copies of the screenshot along with follow-up questions regarding the rogue account.
Source: Krebs on Security