Snow
Snow is identified in reporting as a nickname/handle of an alleged botmaster involved in operating the Aisuru/Kimwolf botnet ecosystem. The Kimwolf botnet is described as mass-compromising unofficial/unsanctioned Android TV streaming boxes at scale (reported as >2 million infected devices) and then coercing infected devices to conduct DDoS attacks and relay abusive/malicious traffic as “residential proxy” exit nodes. XLab reported “definitive evidence” linking Kimwolf to the earlier Aisuru botnet via shared infrastructure and code evolution, including observation of both strains being distributed from the same IP (93.95.112[.]59). The operation is also described as leveraging proxy-related tooling and services (including installation of ByteConnect/Plainproxies SDK and involvement of Maskify in selling access to Kimwolf proxies), with observed downstream activity including credential-stuffing traffic when connecting to ByteConnect’s SDK. After public reporting, the operators allegedly retaliated by deleting Discord history, doxing a researcher (Benjamin Brundage of Synthient), and launching DDoS attacks against Synthient. The operators reportedly adopted Ethereum Name Service (ENS) text records as a resilient C2 discovery mechanism by updating ENS records with new control-server IPs and also used ENS to post taunting/doxing messages. Another alleged controller named alongside Snow is “Dort” (suggested to be associated with a Discord username “D”); a source (“Forky”) claimed Dort (a resident of Canada) and Snow were among those controlling Aisuru/Kimwolf.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet operator/botmaster associated with controlling and operating the Aisuru/Kimwolf botnet, tied to proxy monetization and DDoS activity.
Named botmaster/operator associated with control of the Aisuru/Kimwolf botnet, involved in proxy-enabled abuse and DDoS operations; appears part of the same operator set as Dort.
Named botmaster/operator associated with controlling the Aisuru/Kimwolf botnet used for DDoS and residential proxy abuse; referenced alongside Dort as part of the current control of the botnet.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.