Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
BotNet

DoJ Disrupts Kimwolf Botnet: 3 Million Devices Behind DDoS Attacks

By ogwatermelon
May 24, 2026 4 Min Read
0
May 24, 2026

The U.S. Department of Justice announced on March 20, 2026, a major international law enforcement operation that disrupted command-and-control infrastructure powering four massive IoT botnets. This operation successfully dismantled the Kimwolf botnet along with three others responsible for record-breaking distributed denial-of-service attacks reaching 31.4 terabits per second.

What Happened: DoJ Disrupts World’s Largest IoT Botnets

The U.S. Department of Justice executed a court-authorized operation targeting the infrastructure behind four major botnets. These include Kimwolf, AISURU, JackSkid, and Mossad. The operation represents one of the largest botnet disruptions in history.

International cooperation played a crucial role in this takedown. Canadian and German authorities assisted in targeting the operators. Private sector firms including Akamai, Amazon Web Services, Cloudflare, DigitalOcean, Google, Lumen, Nokia, Okta, Oracle, PayPal, SpyCloud, Synthient, Team Cymru, Unit 221B, and QiAnXin XLab provided essential support.

Technical Details of the Botnets

The four botnets collectively infected more than three million devices worldwide. These compromised devices included digital video recorders, web cameras, Wi-Fi routers, Android smart TVs, and set-top boxes. Hundreds of thousands of these infected devices were located within the United States.

Kimwolf represented a significant evolution in botnet tactics. Unlike traditional botnets that scan the open internet for vulnerable devices, Kimwolf exploited residential proxy networks to infiltrate home networks. The botnet gained access through compromised streaming TV boxes and IoT devices with Android Debug Bridge exposed.

Attack Scale and Impact

The combined botnets issued hundreds of thousands of DDoS attack commands:

  • AISURU: Over 200,000 DDoS attack commands
  • Kimwolf: Over 25,000 DDoS attack commands
  • JackSkid: Over 90,000 DDoS attack commands
  • Mossad: Over 1,000 DDoS attack commands

The November 2025 attack peaked at 31.4 Tbps. Cloudflare described this traffic as equivalent to the combined populations of the UK, Germany, and Spain all simultaneously typing a website address and hitting enter at the same second. The attack lasted only 35 seconds but demonstrated unprecedented scale.

Botnet Monetization Model

The operators employed a cybercrime-as-a-service model. They sold access to infected devices to other cybercriminals. These customers then used the botnet infrastructure to conduct DDoS attacks against targets worldwide. Some attackers demanded extortion payments from victims.

Business and Operational Impact

The impact of these botnets extended across multiple sectors. Akamai reported that the hyper-volumetric botnets generated attacks exceeding 30 Tbps, 14 billion packets per second, and 300 million requests per second. Such attacks can cripple core internet infrastructure.

Service degradation affected ISPs and their downstream customers. High-capacity cloud-based mitigation services faced challenges handling this volume. The economic impact included operational downtime, mitigation costs, and extortion payments.

Lumen Black Lotus Labs null-routed nearly 1,000 C2 servers used by AISURU and Kimwolf. JackSkid averaged over 150,000 daily victims in early March 2026, reaching 250,000 on March 8. Mossad averaged over 100,000 daily victims during the same period.

Attribution and Investigation

Independent security journalist Brian Krebs traced the Kimwolf administrator to a 23-year-old Jacob Butler from Ottawa, Canada. Butler claimed someone compromised his old account and impersonated him. Another prime suspect is reportedly a 15-year-old residing in Germany. No arrests have been announced as of the DoJ disclosure.

Multiple security firms contributed evidence to the investigation. XLab provided sample hashes, decrypted C2 configurations, and screenshots of DDoS attacks. The collaborative effort between law enforcement and private industry proved essential to this operation’s success.

Mitigation and Recommendations

Immediate Actions for Defenders

  1. Audit IoT devices: Inventory all connected devices including smart TVs, set-top boxes, cameras, and routers
  2. Disable Android Debug Bridge: Turn off ADB on Android devices unless specifically required for development
  3. Segment networks: Isolate IoT devices from critical business systems
  4. Monitor for infection indicators: Look for unusual outbound traffic patterns or connections to known C2 infrastructure
  5. Apply firmware updates: Patch all IoT devices with the latest manufacturer updates

Long-Term Security Measures

Organizations should implement zero-trust networking principles for IoT deployments. Additionally, network monitoring solutions must detect anomalous traffic patterns characteristic of botnet participation. Furthermore, security teams should maintain awareness of residential proxy network vulnerabilities that botnets exploit.

Bottom line: The Kimwolf takedown demonstrates both the scale of modern IoT botnet threats and the effectiveness of coordinated public-private partnerships. However, the vulnerability exploitation techniques used by these botnets continue to be emulated by new threats. Organizations must prioritize IoT security and network segmentation to prevent becoming part of the next massive botnet.

Incident Summary

Incident: Kimwolf/AISURU Botnet Takedown
Date Announced: March 20, 2026
Affected Devices: 3+ million IoT devices (Android TVs, set-top boxes, DVRs, cameras, routers)
Botnets Disrupted: Kimwolf, AISURU, JackSkid, Mossad
Peak Attack Size: 31.4 Tbps (November 2025)
Attack Duration: 35 seconds (record attack)
Primary Infection Vector: Residential proxy networks, exposed Android Debug Bridge
Monetization: Cybercrime-as-a-service model selling DDoS capabilities
Status: C2 infrastructure disrupted via court-authorized operation

References

  1. U.S. Department of Justice, “Authorities Disrupt World’s Largest IoT DDoS Botnets Responsible for Record-Breaking Attacks,” March 20, 2026, https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks
  2. The Hacker News, “DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks,” March 20, 2026, https://thehackernews.com/2026/03/doj-disrupts-3-million-device-iot.html
  3. Cloudflare Blog, “DDoS Threat Report 2025 Q4,” February 2026, https://blog.cloudflare.com/ddos-threat-report-2025-q4/
  4. Krebs on Security, “Who Is the Kimwolf Botmaster ‘Dort’?” February 2026, https://krebsonsecurity.com/2026/02/who-is-the-kimwolf-botmaster-dort/
  5. Akamai Security Research, “Akamai Helps Disrupt World’s Largest IoT Botnets,” March 2026, https://www.akamai.com/blog/security-research/akamai-helps-disrupt-worlds-largest-iot-botnets
Author

ogwatermelon

Follow Me
Other Articles
Previous

Ubiquiti Patches Three Maximum Severity UniFi OS Vulnerabilities

Next

Ghost CMS SQL Injection CVE-2026-26980: ClickFix Campaign Hits 700+ Domains

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.