Dort
Dort (also abbreviated as “D”) is an alleged cybercriminal operator associated with the Aisuru and Kimwolf botnets. In the referenced reporting, Dort is suggested to be the owner of the resi[.]to Discord server used to market and coordinate residential proxy services benefiting from Aisuru/Kimwolf-infected devices. A source (“Forky,” described as a Brazilian man who acknowledged early involvement in marketing Aisuru) claimed Dort is a resident of Canada and is one of at least two individuals currently controlling the Aisuru/Kimwolf botnet, alongside another alleged botmaster nicknamed “Snow.” Kimwolf is described as a destructive botnet that mass-compromised unofficial Android TV streaming boxes (over two million devices) and forced infected devices to conduct DDoS attacks and relay abusive traffic for residential proxy services. XLab reported “definitive evidence” linking Kimwolf to the earlier Aisuru botnet via shared infrastructure and code evolution, including observation of both strains being distributed from the same IP (93.95.112[.]59). After publication of the initial Kimwolf story, the operators allegedly retaliated by erasing Discord history, doxing a researcher (Benjamin Brundage of Synthient), and launching DDoS attacks against Synthient. The operators also reportedly adopted Ethereum Name Service (ENS) text records as a resilient mechanism for botnet command-and-control discovery and for posting taunting/doxing messages, with XLab documenting mid-December 2025 infrastructure upgrades to use ENS records to publish updated control-server IPs.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet operator/botmaster associated with controlling and operating the Aisuru/Kimwolf botnet infrastructure, including proxy monetization and DDoS capability.
Named botnet operator/botmaster associated with the Aisuru/Kimwolf botnet ecosystem, tied to residential proxy monetization and DDoS activity; linked to resi[.]to Discord operations and subsequent migration to Telegram after exposure.
Named botmaster/operator associated with controlling the Aisuru/Kimwolf botnet infrastructure used for DDoS and residential proxy abuse; linked to the resi[.]to Discord server administration and subsequent operational security reactions (chat log deletion, migration to Telegram, doxing).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.