Kimwolf and Aisuru linked as a shared botnet operator ecosystem
Threat Actor Meta
Summary
Hide ▲
Show ▼
XLab tied Kimwolf and Aisuru to a shared operator set after confirming both strains were distributed from 93.95.112[.]59 on December 8, 2025. The overlap, suspected since October 2025, supports a single botnet ecosystem used for DDoS and residential proxy abuse. A later deep dive on December 17, 2025 said Kimwolf infected more than two million devices through compromised Android TV streaming boxes and was also used for credential-stuffing and takedown resistance via ENS records.
Related Happenings
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score69
First: 12.06.2026 21:59
Last: 12.06.2026 21:59
Sources 1
About this happening:
The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Sniper Dz free PhaaS ecosystem rebranded to scale phishing operations
Threat Actor Meta
H score43
First: 12.06.2026 11:52
Last: 12.06.2026 11:52
Sources 1
About this happening:
A long-running Sniper Dz ecosystem operated as a free phishing-as-a-service (PhaaS) platform that repeatedly rebranded, lowering the barrier for large-scale credential the...
Sniper Dz free PhaaS ecosystem rebranded to scale phishing operations
Threat Actor MetaAbout this happening: A long-running Sniper Dz ecosystem operated as a free phishing-as-a-service (PhaaS) platform that repeatedly rebranded, lowering the barrier for large-scale credential the...
Latest development: 15.06.2026 09:30
Fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations targeted users across the Middle East and North Africa with fake offers for free mobile internet packages, financial compensation, and government subsidy programs, then routed victims through Linkbio and Linktree decoy pages into Sniper Dz phishing and traffic monetization infrastructure that abuses browser notification permissions, back-button hijacking, tab-under redirections, premium SMS subscriptions, premium-rate calls, and investment scams.
Underground DDoS sellers commoditize attack services with panels, API access, and reseller plans
Threat Actor Meta
H score20
First: 29.05.2026 17:32
Last: 29.05.2026 17:32
Sources 1
About this happening:
Underground DDoS sellers are shifting from scattered tools to packaged, resellable services, lowering the barrier for disruptive attacks and widening the buyer pool. Listings...
Underground DDoS sellers commoditize attack services with panels, API access, and reseller plans
Threat Actor MetaAbout this happening: Underground DDoS sellers are shifting from scattered tools to packaged, resellable services, lowering the barrier for disruptive attacks and widening the buyer pool. Listings...
TeamPCP supply-chain ecosystem shift and extortion partnerships
Threat Actor Meta
H score15
First: 22.05.2026 14:55
Last: 22.05.2026 14:55
Sources 1
About this happening:
TeamPCP has expanded its supply-chain abuse model across open-source ecosystems, raising the risk of downstream compromise and extortion at scale. The group has corrupted hu...
TeamPCP supply-chain ecosystem shift and extortion partnerships
Threat Actor MetaAbout this happening: TeamPCP has expanded its supply-chain abuse model across open-source ecosystems, raising the risk of downstream compromise and extortion at scale. The group has corrupted hu...
Timeline
-
17.12.2025 02:00 2 articles · 7mo ago
Kimwolf and Aisuru shared operators confirmed on December 8, 2025
Attribution UpdateXLab confirmed that Kimwolf and Aisuru were being distributed by the same Internet address at 93.95.112[.]59, resolving suspicions that had existed since October 2025 and supporting the assessment that both botnet strains shared operators and infrastructure.
Show sources
- Who Benefited from the Aisuru and Kimwolf Botnets? — krebsonsecurity.com — 09.01.2026 01:23
- Who Benefited from the Aisuru and Kimwolf Botnets? — krebsonsecurity.com — 09.01.2026 01:23
-
17.12.2025 02:00 1 articles · 7mo ago
XLab deep dive documents shared Kimwolf and Aisuru infrastructure on December 17, 2025
Technical Analysis UpdateXLab published a deep dive on Kimwolf describing definitive evidence that the same cybercriminal actors and infrastructure were used to deploy both Kimwolf and the earlier Aisuru botnet, tying the ecosystem to DDoS attacks and residential proxy abuse.
Show sources
- Who Benefited from the Aisuru and Kimwolf Botnets? — krebsonsecurity.com — 09.01.2026 01:23