7–9 Apr 2026
Jaarbeurs Supernova
Europe/Amsterdam timezone

Security Days Organisational Committee

The $30 Trojan horse: How off-brand Android TV boxes became DDoS infrastructure

8 Apr 2026, 12:00
25m
Mission 1 Room (Jaarbeurs Supernova)

Mission 1 Room

Jaarbeurs Supernova

Utrecht, Netherlands
Single Presentation (25 min) Presentations 1 DDoS Mitigation

Speaker

Jérôme Meyer (Nokia)

Description

In October 2025, Nokia Deepfield observed a 33 terabits-per-second DDoS attack against a gaming provider—a volume exceeding the total capacity of many national internet backbones. Terabit-scale attacks are now a daily occurrence, with 78% of campaigns concluding in under five minutes. The era of IoT botnets has given way to something far more insidious: residential proxy networks commanding an estimated 100 to 200 million consumer endpoints.

The attack surface has shifted. Budget Android TV boxes—sold for as little as $30 on mainstream marketplaces—increasingly ship with malware pre-installed at the factory or embedded in unofficial firmware updates. These devices arrive backdoored—not through user negligence, but compromised supply chains. The malware activates silently, enrolling each device into distributed attack infrastructure while the owner streams content unaware.

This presentation examines Kimwolf, a sophisticated botnet we analyzed extensively in a controlled laboratory environment, which exemplifies this new threat model. Unlike traditional botnets that scan for vulnerable IoT devices, Kimwolf recruits its army through a different vector: uncertified Android TV boxes, mobile phones with "free" VPN applications, and backdoored home routers. These devices sit behind NAT, invisible to external scanning, yet capable of generating attack traffic that dwarfs what security teams prepared for even two years ago.

Why should the R&E community care? Because these devices are already on your networks. Budget streaming boxes in student housing. Mobile devices running apps with embedded proxy SDKs. None of these require user error to become compromised—they arrive that way. Every affected device becomes a node in attack infrastructure that may target your own institution, or turn your network into an unwitting participant in attacks against others.

Our Kimwolf analysis revealed a multi-vector threat: UDP floods exceeding 500 Mbps from single nodes, credential stuffing campaigns against Microsoft and Instagram, and active recruitment into the PacketStream residential proxy network. The malware uses Ethereum Name Service (ENS) for resilient command-and-control, receives campaign-specific attack orders, and evades detection through sophisticated anti-analysis techniques.

What will attendees learn?

  • The supply chain problem: how budget Android devices ship pre-compromised and why traditional endpoint security cannot address factory-installed malware
  • The architectural shift from IoT botnets to residential proxy networks, and why scanning-based threat intelligence fails against NAT-hidden devices
  • Inside Kimwolf: technical analysis of a modern DDoS botnet including C2 communication patterns, ENS-based infrastructure, and multi-vector attack capabilities
  • Detection strategies for identifying compromised devices on campus networks before they participate in attacks
  • The 100 Tbps horizon: what current attack growth trajectories mean for R&E network planning and why sub-60-second detection is now essential
  • Disrupting botnets at the edge: why dynamic blocking of C2 communication at network boundaries will become an increasingly important defensive measure

The research and education community has historically been both target and unwitting participant in DDoS attacks. As residential proxy botnets blur the line between attacker and victim infrastructure, NRENs must evolve from reactive defense to proactive identification of compromised endpoints within their constituencies. This session provides the threat intelligence and practical detection approaches needed to begin that transition.

The presentation will include examples of captured attack traffic, C2 communication patterns, and detection signatures derived from our research.


Format: Presentation (25-30 minutes)
Track: Security Operations / Technical Deep Dive
Keywords: DDoS, botnets, residential proxies, threat intelligence, IoT security

Author

Jérôme Meyer (Nokia)

Presentation materials