Kimwolf reportedly infected more than two million unofficial Android TV boxes

THE BRIEF
Krebs on Security reports that the Kimwolf botnet spread by mass-compromising unofficial Android TV streaming boxes, with more than two million devices reportedly infected. The account follows a Dec. 17, 2025 investigation by Chinese security firm XLab, which said Kimwolf makes compromised devices participate in distributed denial-of-service (DDoS) attacks and relay abusive or malicious internet traffic for “residential proxy” services. The report says the software used to turn devices into residential proxies is often quietly bundled with mobile apps and games. Kimwolf reportedly focused on residential-proxy software factory-installed on more than 1,000 models of unsanctioned Android TV streaming devices. Krebs’ follow-up examines digital clues associated with the hackers, network operators and services that appear to have benefited from the botnet’s spread. The supplied account does not identify the beneficiaries or provide additional findings, so the claims should be treated as reported rather than independently verified here.
WHY IT MATTERS
The report links consumer streaming hardware, bundled software and residential-proxy services to a botnet allegedly capable of both DDoS activity and abusive traffic relaying. That combination illustrates how unofficial or unsanctioned devices can become part of infrastructure used by others without the owner’s clear awareness. The reported scale—more than two million devices—also makes device provenance and software supply decisions relevant beyond individual households. Organizations and consumers should distinguish the reported findings from independently verified facts while considering how unmanaged Android TV equipment and quietly bundled applications fit into their security exposure.
WHO SHOULD CARE
Security teams, device fleet managers, consumer technology buyers, and organizations that permit Android TV streaming devices on their networks should review the reported risks around unofficial hardware, bundled applications, and residential-proxy software.
WHAT TO DO NOW
- Inventory Android TV streaming devices connected to organizational networks and identify whether they are official or unsanctioned models.
- Review installed applications and games on those devices for quietly bundled residential-proxy software or other unfamiliar components.
- Restrict or isolate unofficial streaming boxes from sensitive networks until their software and provenance can be assessed.