Synapse Consulting
Home SynapseRM / TPRM Services Pricing About BlogCareersLabsContact
EN · FR
Test access Book a demo
BOTNET / IoT

Kimwolf: the botnet that hides its brain on the blockchain

A botnet that infects Android TV boxes sounds like someone else’s problem. Kimwolf is worth a second look, not for what it infects, but for how it stays alive: it hides its command channel on the Ethereum blockchain, where you cannot simply take it down.

SYNAPSE CONSULTING  ·  13 AUGUST 2026  ·  2 MIN READ

A boring front door

Kimwolf does not use a clever exploit to get in. It looks for devices that expose the Android Debug Bridge on port 5555 with no authentication, a setting that ships enabled on a surprising number of cheap TV boxes and set-top devices. Reach the port, push the app, done. The whole first stage is a configuration failure, not a vulnerability.

Exposed ADBTV box, port 5555 Silent installno auth, netd_service Redundant C2Ethereum ENS (5 RPC)Tor hidden servicelocal proxy :23075 DDoS fleet15 methods, L3 to L7
Kimwolf’s chain: an exposed debug port, a silent install, a command channel spread across Ethereum, Tor and a local proxy, feeding a DDoS fleet.

The part worth studying

The interesting engineering is the command-and-control. Instead of a hard-coded server that defenders can sinkhole, Kimwolf resolves its controller through Ethereum name records, queried across five hard-coded RPC endpoints, with a Tor hidden service and a local proxy as fallbacks. Blockchain records are not something an incident responder can take down with an abuse report. The malware masks its process as netd_service and listens on localhost 23075. Once it has a foothold, the device joins a DDoS fleet with fifteen attack methods spanning OSI layers three to seven.

Why this is not just a consumer story

Two reasons it reaches the enterprise. First, shadow IT: a TV box in a meeting room or a reception screen sits on your network and nobody assessed it. Second, the pattern generalises. Unauthenticated management interfaces and takedown-resistant C2 are exactly what you will meet again on OT gear, cameras and building systems. Kimwolf is a clean illustration of a class.

Mitigations

What it means for your register

Kimwolf is a reminder that your attack surface includes the assets nobody wrote down. A device that is not in the inventory cannot be assessed, cannot be assigned an owner, and cannot be patched. This is why the asset referential and the business-impact assessment come before the risk assessment: the reception screen running an unpatched TV box is low criticality on confidentiality but sits on the same VLAN as something that is not. The risk is not the botnet. The risk is the asset you did not know you had.

Technical detail from Unit 42’s analysis at Palo Alto Networks Unit 42.

NEXT STEP
Bring us one real project

In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.

Book a demo Request test access
Synapse Consulting

A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.

PLATFORM
SynapseRM / TPRM Pricing Test accessPresentation (PDF)
SERVICES
Governance Operational Training
COMPANY
About Contact Blog Careers Labs Privacy & cookies
Brussels, Belgium