Table of Contents
ToggleA 2 million device Android botnet called Kimwolf has been spreading by hijacking the very residential proxy networks that scraping and SEO teams rely on, and security researchers say the underlying flaw is still not fully fixed.
Kimwolf infects cheap, unofficial Android TV boxes, then resells their bandwidth as “residential” proxy IPs without the device owner’s knowledge
The botnet has produced roughly 12 million unique IP addresses a week, most concentrated in Vietnam, Brazil, India, and Saudi Arabia
Compromised devices get used for DDoS attacks, ad fraud, account takeovers, and mass scraping, not just proxy resale
How it spreads

Security firm Synthient traced Kimwolf’s growth to a specific weakness: many proxy providers were not blocking their own customers from reaching into the local network of the device running the proxy.
That let attackers tunnel through legitimate-looking residential proxy traffic straight into unsecured Android TV boxes running an exposed Android Debug Bridge service. Two out of three infected devices had no authentication at all.
Why it matters for proxy buyers
This is the exact risk that separates ethical, verified residential proxy networks from botnet-fed ones. A meaningful share of cheap “residential” IP pools on the market are sourced from devices that never consented to being proxy nodes, sold pre-infected by the hardware vendor itself. Synthient found some devices shipped with modified provider SDKs baked in before they ever reached a customer.
What’s being done
One major provider, IPIDEA, patched the exposed ports in December after Synthient’s disclosure. Synthient recommends proxy providers block access to local network addresses by default, and it offers a free check at synthient.com to see if a device is part of the botnet, with destruction recommended for anything flagged.
Quick Links: