Kimwolf IoT Botnet Reportedly Reaches More Than 2 Million Devices

THE BRIEF
Krebs on Security reports that a newly identified IoT botnet called Kimwolf has spread to more than 2 million devices. The report says infected systems are being used in large distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive internet traffic. Kimwolf reportedly grew quickly in the final months of 2025 by persuading residential-proxy services to relay malicious commands to devices on the local networks of proxy endpoints. Those services sell access intended to anonymize and localize web traffic, and the report says the largest allow customers to route internet activity through them. Kimwolf can also scan the local networks of compromised systems for additional IoT devices to infect. New research cited by Krebs on Security indicates the botnet is present in corporate and government networks, making unmanaged or exposed IoT equipment an organizational concern. The report does not establish the extent of impact for any particular organization.
WHY IT MATTERS
Kimwolf matters because the reported infection path reaches beyond individual IoT devices: compromised systems may scan nearby networks for more devices, while also supporting DDoS attacks and relaying other traffic. Its reported presence in corporate and government networks raises questions about visibility into connected equipment and about the exposure created when residential-proxy services can reach local devices. The available report does not identify specific affected organizations or quantify operational damage, so the prudent takeaway is preparedness: find IoT assets, understand their network relationships, and look for unusual scanning or traffic patterns.
WHO SHOULD CARE
Security and IT teams in corporate and government environments should care, especially those responsible for IoT inventories, network monitoring, DDoS resilience, or third-party and proxy-service risk. Organizations using connected devices can use the report as a prompt to review visibility and segmentation.
WHAT TO DO NOW
- Build or update an inventory of IoT devices, including their network locations and responsible owners.
- Review network segmentation and access controls for IoT devices and local networks to limit unnecessary device-to-device reachability.
- Monitor for unexpected local-network scanning, DDoS-related activity, or unusual traffic relaying from connected devices.
- Assess whether residential-proxy or similar third-party services can relay traffic to devices on local networks, and document relevant controls.