Looks like the Aisuru botnet group created another botnet named Kimwolf that they are now using for DDoS attacks
-1.83m infected systems
-most are Android devices
-uses EtherHiding and Tor
Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices
Background On October 24, 2025, a trusted partner in the security community provided us with a brand-new botnet sample. The most distinctive feature of this sample was its C2 domain, 14emeliaterracewestroxburyma02132[.]su, which at the time ranked 2nd in the Cloudflare Domain Rankings. A week later, it even surpassed Google
奇安信 X 实验室 (blog.xlab.qianxin.com)
