
On October 30th, Cloudfare data identified a strange website that briefly surpassed Google as the most popular website globally. However, it wasn’t a website at all – It was a massive command-and-control server that was controlling at least 1.8 million Android devices in order to use them for nefarious purposes.
Known as Kimwolf, the botnet is now considered to be the largest of its kind (so far) and shares codebase with the previous recordbreaker, Aisuru. Though both botnets use malware to infect vulnerable devices and rely on an APK file to load and start during runtime, the threat actors learned from Aisuru and included additional features in Kimwolf to better evade detection. Capable of various malicious activities including typical DDoS attacks, it also uses proxy forwarding which allows the attackers to conceal their location and lets them bypass IP-based geo-restrictions and blacklists.