KimWolf quietly hijacked nearly 2 million Android and consumer devices — TV boxes, cameras, picture frames — and turned them into a single, monstrous cyberweapon. Experts feared it could knock out the internet entirely.
A 22-year-old college student cracked the world's biggest botnet from his dorm room using a cat meme, an old Android phone, and a DIY honeypot — then got thanked by the DOJ.
The Journal.
A 22-year-old college student cracked the world's biggest botnet from his dorm room using a cat meme, an old Android phone, and a DIY honeypot — then got thanked by the DOJ.
TL;DR
A 22-year-old college senior named Benjamin Brundage stumbled onto KimWolf — the largest botnet ever observed — while researching shady residential proxy networks from his dorm room [1] — Jessica Mendoza "KimWolf quietly hijacked nearly 2 million Android and consumer devices — TV boxes, cameras, picture frames — and turned them into a single,…" . Using Discord cat memes, a DIY honeypot Android phone, and 2 million cataloged IP addresses, Ben cracked the mystery that stumped professional cybersecurity teams [2] — Benjamin Brundage "Ben Brundage installed IP Idea's software on an old Android phone via a pirated streaming app and monitored all traffic coming in and out. …" 26:30 . His findings helped Google, the DOJ, and a working group called Big Pipes dismantle a network behind 26,000+ DDoS attacks [3] — Jessica Mendoza "DOJ seized domains in March 2025: Two months after Google's action, the DOJ struck against four of the world's largest DDoS botnets, includ…" 33:25 . The key takeaway: the internet has an "internet pollution" problem, filled with compromised consumer devices few know how to fix.
WSJ reporter Robert McMillan investigates KimWolf, the largest botnet ever observed, and how 22-year-old college student Benjamin Brundage played a critical role in unraveling and helping dismantle it.
The episode opens with a striking framing device: the people who defend the internet are 'wizards,' and over the last year those wizards faced something unlike anything they had ever encountered. WSJ cybersecurity reporter Robert McMillan introduces KimWolf, a fast-growing botnet that quietly hijacked nearly 2 million Android and consumer devices — phones, cameras, TV boxes, picture frames — and turned them into a single, devastating cyberweapon [1] — Jessica Mendoza "KimWolf quietly hijacked nearly 2 million Android and consumer devices — TV boxes, cameras, picture frames — and turned them into a single,…" . McMillan explains what DDoS attacks are: armies of computers flooding a target with junk data until it collapses. KimWolf was doing this at an unprecedented scale, and the wizards' greatest fear was stark: the internet itself could be knocked out. Against this backdrop, Jessica Mendoza teases the episode's hero — a 22-year-old college senior named Benjamin Brundage who would help crack the case from his dorm room.
A brief sponsored segment from Accenture promotes its partnership with Spotify to automate advertising operations, promising smarter workflows, better data access, and more time for teams to focus on connecting brands with audiences. Listeners are directed to accenture.com/spotify for more information.
Tremfya is advertised as a prescription medicine for adults suffering from moderately to severely active Crohn's disease or ulcerative colitis, offering both self-injection and intravenous infusion options. The segment includes full safety disclosures, including risks of serious allergic reactions, infections, and liver problems, and directs listeners to consult their doctors.
Long before he was fighting the world's biggest botnet, Ben Brundage was just a kid who liked hiking and skiing. That changed in 2020 when COVID lockdowns drove him to Minecraft, and the game's modding system sparked a genuine love of code [1] — Benjamin Brundage "Bored during COVID lockdowns, teenager Benjamin Brundage started modding Minecraft and quickly fell into Discord servers where cybercrime w…" 04:44 . Ben learned Java by watching late-night tutorials, built custom plants and creatures, and then discovered the darker side: cheats that let him see through walls and auto-aim at enemies, eventually getting his account banned. On Discord, Minecraft modding communities blurred almost imperceptibly into hacker forums — servers on cybercrime were just a few hops away. Ben recounts how easy it was to get drawn in, describing the normalization that happens when you spend enough time around people who treat cybercrime as routine. His moral alarm bells finally rang when he stumbled on a list of 100 stolen Spotify Premium accounts posted openly in a server — rather than join in, he emailed all 60-some account holders to warn them, a decision that set the direction of his life.
Recognizing that the road he was on with hacking communities wasn't going to end well, Ben Brundage made a deliberate pivot toward cybersecurity. His first real test came in his senior year of high school, when the Dutch government opened an invitation to hackers worldwide to find vulnerabilities in its websites [1] — Benjamin Brundage "As a high school senior, Ben found two major security bugs in Dutch government websites during an open bug-bounty program. His reward: a bl…" 10:20 . Ben submitted not one but two major bugs. The reward was a black t-shirt emblazoned with 'Hacked the Dutch government, and all I got was this lousy t-shirt' — a joke prize that nonetheless gave Ben a genuine rush. He carried that energy into Rochester Institute of Technology, where he studied computer science and taught himself to automate tasks and build bots. That skill set, assembled without any awareness of what was coming, was about to point him directly at KimWolf.
Every device on the internet has an IP address — essentially a phone number — that websites use to identify who's visiting. Residential proxy networks exploit that by letting third parties route their traffic through someone else's home IP, making the traffic look like it comes from an ordinary household [1] — Robert McMillan "Residential proxy networks let companies rent out your home IP address to route anonymous internet traffic — sometimes without your consent…" 11:16 . McMillan uses the Airbnb analogy: you might be unknowingly renting out your internet address. Some residential proxy companies obtain these IPs legitimately; others do not. The shadiest ones sneak malware onto devices through pirated streaming apps or sell cheap internet-connected gadgets — TV boxes, picture frames — with proxy software pre-installed. The criminal applications are extensive: covering the tracks of nation-state hackers, helping ticket scalpers buy in bulk, enabling identity fraud. Ben, still a college student, found himself fascinated by this obscure corner of the internet, sensing that something bigger was hiding beneath it.
By August of last year, Ben had turned his hobby research into a one-man company — Synthient — and was building a comprehensive database of suspicious residential proxy IP addresses. Browsing the landscape of res proxy providers, he noticed something that didn't add up: the websites were eerily identical. Same checkout flow, same user interface, just different branding and color schemes [1] — Jessica Mendoza "IP Idea operated under 12+ brand names: The residential proxy company IP Idea appeared to operate under more than a dozen different brand n…" 16:00 . Digging deeper, he traced all of them back to a single entity: IP Idea. The company was enigmatic — no CEO listed, no founder, no address, more than a dozen operating brands. What especially stood out was what it lacked: the guardrails most proxy companies have to prevent their networks from being used for fraud. IP Idea had none. Ben published an online tool on Discord that let users check whether their IP was in his database — and that's when a mysterious message arrived.
A week after Ben posted his IP-address tool on Discord, a message arrived from an unknown user who said, in effect, 'Nice try — you missed some.' The user attached screenshots proving it [1] — Benjamin Brundage "When Ben Brundage wanted to keep a KimWolf-connected hacker talking without spooking them, he sent a cat GIF — a tuxedo-wearing cat meant t…" 18:48 . Ben could tell from their typing style — the casual abbreviations, the GIFs, the emoji use — that this was probably someone close to his own age, not a seasoned criminal. Rather than confronting them, Ben played it cool, responding with a GIF of a cat in a tuxedo to signal he wasn't a threat. It worked. The hacker opened up, revealing they had a 'novel exploit' for gaining access to devices, that they were running a botnet-for-hire service, and — most alarmingly — that the operation was spending $30,000 a month on infrastructure, was 'not some rinky-dink operation,' and came with an explicit message: don't investigate us. For Ben, those three data points lit up like red flags, confirming that something far larger was going on.
The thing Ben had stumbled into wasn't just a botnet — it was KimWolf, the most extreme botnet operation ever observed [1] — Jessica Mendoza "One attack = entire Germany+Spain+UK: One KimWolf DDoS attack was so large it was as if everyone in Germany, Spain, and the UK had visited …" 20:15 . A single attack had traffic equivalent to every person in Germany, Spain, and the United Kingdom hitting the same website at the exact same second. Cybersecurity professionals had been tracking it for months. Chris Formosa, an engineer at the networking company Lumen, had been focusing his research on IP Idea specifically, watching the botnet grow at an unchecked pace. But the central mystery remained unsolved: nobody knew how KimWolf was getting its victims. The worry was that the network had millions of IP addresses and no one checking what was happening on it — a situation ripe for catastrophic abuse.
When a mutual contact told Chris Formosa there was someone he needed to meet, he didn't expect a 22-year-old college student. But from the moment they connected, the collaboration was electric: their first conversation lasted 8 hours, with notes flying back and forth between them [1] — Chris Formosa "8 hours first conversation with Chris: When Ben Brundage first connected with Lumen engineer Chris Formosa, they chatted for 8 hours straig…" 22:32 . Ben shared what he'd learned about IP Idea and the details he'd extracted from his Discord conversations with the anonymous hacker. Chris quickly realized Ben's Discord contact was likely connected to KimWolf itself. Shortly after, Chris introduced Ben to Big Pipes — a secretive working group of engineers from major internet companies, the 'wizards' who monitor the actual flows of data across the internet's backbone. Ben joined their weekly conference calls, a college student suddenly sitting at the same table as the people running the infrastructure of the internet.
For months, Big Pipes had been watching KimWolf's attacks but couldn't figure out how the hackers were enrolling devices. Then one of their own members noticed something alarming: their own IP address was being used in an attack [1] — Robert McMillan "The breakthrough in the KimWolf investigation came when a Big Pipes employee discovered that their own IP address was launching attacks. Th…" 24:08 . They asked the employee to investigate their home network. The culprit turned out to be a $50 digital picture frame — the kind you update with photos from your phone. This cheap, seemingly harmless device had been secretly conscripted into KimWolf's army. With an actual piece of infected hardware in hand for the first time, Big Pipes had a concrete object to tear apart and study. Now the question was: how exactly was KimWolf getting in? That answer would have to come from Ben.
A brief sponsored segment from Intuit promotes the Intuit Enterprise Suite, described as a powerful, painless, and proven AI-native ERP solution for finance teams dealing with fragmented data sources and the challenges of business scaling.
Ben's big insight was simple but brilliant: if you want to catch something exploiting residential proxy devices, become one [1] — Benjamin Brundage "Ben Brundage installed IP Idea's software on an old Android phone via a pirated streaming app and monitored all traffic coming in and out. …" 26:30 . He installed IP Idea's software on a spare Android phone, downloaded from a website offering pirated streaming content, and built a monitoring setup to capture every byte of traffic coming in and out. Then he waited — balancing the experiment with studying for midterms. Within a week, one domain kept appearing in the traffic logs: xd.resi.to, an address with no obvious connection to IP Idea. Ben immediately flagged it. The domain turned out to be KimWolf's foothold: it was using the residential proxy's own access to the device to pivot from the open internet into the phone's local network — and from there, commandeer the device entirely. As Robert McMillan put it, it was like an Airbnb guest deciding to squat in the rental and rummage through all the locked closets. Ben brought his findings to Big Pipes, and together they confirmed that KimWolf had exploited a bug in IP Idea's own code to pull off this attack at scale.
With the exploit understood, Ben moved to warn the industry. He identified 10 other residential proxy companies vulnerable to the same bug IP Idea had [1] — Jessica Mendoza "Bug found in 11 proxy companies: Ben Brundage discovered that not only IP Idea but 10 other residential proxy companies were also vulnerabl…" 31:15 . As his final exams loomed, he drafted notifications to all of them, sending the emails on December 17th — the day after his last test [2] — Jessica Mendoza "10 million pre-installed devices: Google identified more than 10 million devices that came with IP Idea's software secretly pre-installed o…" 32:50 . IP Idea replied 9 days later, claiming the email had gone to spam and promising a fix. It was too little, too late. In January, Google obtained a US court order and moved decisively: 13 of IP Idea's business domains were taken down and dozens of its servers were shut off. Google had by then identified over 10 million devices pre-installed with IP Idea's software. Two months later, in March, the Department of Justice struck against four of the world's largest DDoS botnets, including KimWolf — seizing domains, virtual servers, and network infrastructure. At the end of the DOJ press release was a list of companies thanked for their help. Among the major tech firms was Synthient: Ben's one-man startup, operating out of a college dorm room.
Despite the Google and DOJ actions, KimWolf hasn't been fully exterminated — it still lurks in thousands of compromised devices, a reminder that botnets are stubbornly resilient. Robert McMillan frames the lasting lesson with characteristic bluntness: the internet is full of junk [1] — Robert McMillan "The real takeaway here is that we have an internet filled with junk. We have garbage devices, garbage apps that are doing a lot of bad stuf…" 34:26 . Garbage devices and garbage apps have quietly become part of the criminal infrastructure, and the problem — what he calls 'internet pollution' — has no clear solution yet. For listeners who want to know if their own network is secretly enrolled in a residential proxy, Bob has written a guide available in the show notes. As for Ben Brundage, the unlikely hero of the whole story, he's now focused on finishing his degree, growing Synthient, and maybe taking his first real vacation in a long time. And if the rumors he's heard are true, there might be a t-shirt in his future — one that says, 'I stopped KimWolf, and all I got was this lousy t-shirt.'
Chapter 1 · 00:00
The episode opens with a striking framing device: the people who defend the internet are 'wizards,' and over the last year those wizards faced something unlike anything they had ever encountered. WSJ cybersecurity reporter Robert McMillan introduces KimWolf, a fast-growing botnet that quietly hijacked nearly 2 million Android and consumer devices — phones, cameras, TV boxes, picture frames — and turned them into a single, devastating cyberweapon [1] — Jessica Mendoza "KimWolf quietly hijacked nearly 2 million Android and consumer devices — TV boxes, cameras, picture frames — and turned them into a single,…" . McMillan explains what DDoS attacks are: armies of computers flooding a target with junk data until it collapses. KimWolf was doing this at an unprecedented scale, and the wizards' greatest fear was stark: the internet itself could be knocked out. Against this backdrop, Jessica Mendoza teases the episode's hero — a 22-year-old college senior named Benjamin Brundage who would help crack the case from his dorm room.
KimWolf quietly hijacked nearly 2 million Android and consumer devices — TV boxes, cameras, picture frames — and turned them into a single, monstrous cyberweapon. Experts feared it could knock out the internet entirely.
KimWolf hijacked nearly 2 million Android and internet-connected devices globally, including TV boxes, cameras, picture frames, and phones.
A DDoS attack floods a target computer with so much junk traffic — fake requests for webpages — that it grinds to a halt. KimWolf weaponized millions of ordinary home devices to do exactly this at an unprecedented scale.
Chapter 4 · 04:43
Long before he was fighting the world's biggest botnet, Ben Brundage was just a kid who liked hiking and skiing. That changed in 2020 when COVID lockdowns drove him to Minecraft, and the game's modding system sparked a genuine love of code [1] — Benjamin Brundage "Bored during COVID lockdowns, teenager Benjamin Brundage started modding Minecraft and quickly fell into Discord servers where cybercrime w…" 04:44 . Ben learned Java by watching late-night tutorials, built custom plants and creatures, and then discovered the darker side: cheats that let him see through walls and auto-aim at enemies, eventually getting his account banned. On Discord, Minecraft modding communities blurred almost imperceptibly into hacker forums — servers on cybercrime were just a few hops away. Ben recounts how easy it was to get drawn in, describing the normalization that happens when you spend enough time around people who treat cybercrime as routine. His moral alarm bells finally rang when he stumbled on a list of 100 stolen Spotify Premium accounts posted openly in a server — rather than join in, he emailed all 60-some account holders to warn them, a decision that set the direction of his life.
Bored during COVID lockdowns, teenager Benjamin Brundage started modding Minecraft and quickly fell into Discord servers where cybercrime was openly discussed. He saw a stolen list of 100 Spotify accounts and chose to warn the victims instead of joining the hackers.
Chapter 5 · 10:20
Recognizing that the road he was on with hacking communities wasn't going to end well, Ben Brundage made a deliberate pivot toward cybersecurity. His first real test came in his senior year of high school, when the Dutch government opened an invitation to hackers worldwide to find vulnerabilities in its websites [1] — Benjamin Brundage "As a high school senior, Ben found two major security bugs in Dutch government websites during an open bug-bounty program. His reward: a bl…" 10:20 . Ben submitted not one but two major bugs. The reward was a black t-shirt emblazoned with 'Hacked the Dutch government, and all I got was this lousy t-shirt' — a joke prize that nonetheless gave Ben a genuine rush. He carried that energy into Rochester Institute of Technology, where he studied computer science and taught himself to automate tasks and build bots. That skill set, assembled without any awareness of what was coming, was about to point him directly at KimWolf.
As a high school senior, Ben found two major security bugs in Dutch government websites during an open bug-bounty program. His reward: a black t-shirt reading 'Hacked the Dutch government, and all I got was this lousy t-shirt.' It was a dopamine rush anyway.
As a high school senior, Ben Brundage found two major security vulnerabilities in Dutch government websites during an open bug-bounty program, earning only a t-shirt.
Residential proxy networks let companies rent out your home IP address to route anonymous internet traffic — sometimes without your consent. Pirated streaming apps and cheap 'too good to be true' TV boxes are common vectors for installing the malware that makes this possible.
Chapter 6 · 12:40
Every device on the internet has an IP address — essentially a phone number — that websites use to identify who's visiting. Residential proxy networks exploit that by letting third parties route their traffic through someone else's home IP, making the traffic look like it comes from an ordinary household [1] — Robert McMillan "Residential proxy networks let companies rent out your home IP address to route anonymous internet traffic — sometimes without your consent…" 11:16 . McMillan uses the Airbnb analogy: you might be unknowingly renting out your internet address. Some residential proxy companies obtain these IPs legitimately; others do not. The shadiest ones sneak malware onto devices through pirated streaming apps or sell cheap internet-connected gadgets — TV boxes, picture frames — with proxy software pre-installed. The criminal applications are extensive: covering the tracks of nation-state hackers, helping ticket scalpers buy in bulk, enabling identity fraud. Ben, still a college student, found himself fascinated by this obscure corner of the internet, sensing that something bigger was hiding beneath it.
Chapter 7 · 15:20
By August of last year, Ben had turned his hobby research into a one-man company — Synthient — and was building a comprehensive database of suspicious residential proxy IP addresses. Browsing the landscape of res proxy providers, he noticed something that didn't add up: the websites were eerily identical. Same checkout flow, same user interface, just different branding and color schemes [1] — Jessica Mendoza "IP Idea operated under 12+ brand names: The residential proxy company IP Idea appeared to operate under more than a dozen different brand n…" 16:00 . Digging deeper, he traced all of them back to a single entity: IP Idea. The company was enigmatic — no CEO listed, no founder, no address, more than a dozen operating brands. What especially stood out was what it lacked: the guardrails most proxy companies have to prevent their networks from being used for fraud. IP Idea had none. Ben published an online tool on Discord that let users check whether their IP was in his database — and that's when a mysterious message arrived.
The residential proxy company IP Idea appeared to operate under more than a dozen different brand names while listing no CEO, founder, or address on its websites.
Chapter 8 · 18:30
A week after Ben posted his IP-address tool on Discord, a message arrived from an unknown user who said, in effect, 'Nice try — you missed some.' The user attached screenshots proving it [1] — Benjamin Brundage "When Ben Brundage wanted to keep a KimWolf-connected hacker talking without spooking them, he sent a cat GIF — a tuxedo-wearing cat meant t…" 18:48 . Ben could tell from their typing style — the casual abbreviations, the GIFs, the emoji use — that this was probably someone close to his own age, not a seasoned criminal. Rather than confronting them, Ben played it cool, responding with a GIF of a cat in a tuxedo to signal he wasn't a threat. It worked. The hacker opened up, revealing they had a 'novel exploit' for gaining access to devices, that they were running a botnet-for-hire service, and — most alarmingly — that the operation was spending $30,000 a month on infrastructure, was 'not some rinky-dink operation,' and came with an explicit message: don't investigate us. For Ben, those three data points lit up like red flags, confirming that something far larger was going on.
When Ben Brundage wanted to keep a KimWolf-connected hacker talking without spooking them, he sent a cat GIF — a tuxedo-wearing cat meant to signal he wasn't taking things too seriously. It worked, and the hacker started sharing operational details about the botnet.
The hacker running the KimWolf botnet told Ben Brundage that the operation spent $30,000 a month on infrastructure.
One KimWolf DDoS attack was so large it was as if everyone in Germany, Spain, and the UK had visited the same website at the exact same second.
Chapter 9 · 21:00
The thing Ben had stumbled into wasn't just a botnet — it was KimWolf, the most extreme botnet operation ever observed [1] — Jessica Mendoza "One attack = entire Germany+Spain+UK: One KimWolf DDoS attack was so large it was as if everyone in Germany, Spain, and the UK had visited …" 20:15 . A single attack had traffic equivalent to every person in Germany, Spain, and the United Kingdom hitting the same website at the exact same second. Cybersecurity professionals had been tracking it for months. Chris Formosa, an engineer at the networking company Lumen, had been focusing his research on IP Idea specifically, watching the botnet grow at an unchecked pace. But the central mystery remained unsolved: nobody knew how KimWolf was getting its victims. The worry was that the network had millions of IP addresses and no one checking what was happening on it — a situation ripe for catastrophic abuse.
When Ben Brundage first connected with Lumen engineer Chris Formosa, they chatted for 8 hours straight passing notes back and forth about IP Idea.
Chapter 10 · 23:00
When a mutual contact told Chris Formosa there was someone he needed to meet, he didn't expect a 22-year-old college student. But from the moment they connected, the collaboration was electric: their first conversation lasted 8 hours, with notes flying back and forth between them [1] — Chris Formosa "8 hours first conversation with Chris: When Ben Brundage first connected with Lumen engineer Chris Formosa, they chatted for 8 hours straig…" 22:32 . Ben shared what he'd learned about IP Idea and the details he'd extracted from his Discord conversations with the anonymous hacker. Chris quickly realized Ben's Discord contact was likely connected to KimWolf itself. Shortly after, Chris introduced Ben to Big Pipes — a secretive working group of engineers from major internet companies, the 'wizards' who monitor the actual flows of data across the internet's backbone. Ben joined their weekly conference calls, a college student suddenly sitting at the same table as the people running the infrastructure of the internet.
Big Pipes is an elite cybersecurity working group of engineers from major internet companies who quietly defend the internet's infrastructure. When they recruited Ben Brundage for their weekly calls, they got something the wizards lacked: a Discord-native who could talk to hackers using cat memes.
Chapter 11 · 24:08
For months, Big Pipes had been watching KimWolf's attacks but couldn't figure out how the hackers were enrolling devices. Then one of their own members noticed something alarming: their own IP address was being used in an attack [1] — Robert McMillan "The breakthrough in the KimWolf investigation came when a Big Pipes employee discovered that their own IP address was launching attacks. Th…" 24:08 . They asked the employee to investigate their home network. The culprit turned out to be a $50 digital picture frame — the kind you update with photos from your phone. This cheap, seemingly harmless device had been secretly conscripted into KimWolf's army. With an actual piece of infected hardware in hand for the first time, Big Pipes had a concrete object to tear apart and study. Now the question was: how exactly was KimWolf getting in? That answer would have to come from Ben.
The breakthrough in the KimWolf investigation came when a Big Pipes employee discovered that their own IP address was launching attacks. The culprit: a $50 digital picture frame on their home network, secretly turned into a DDoS weapon.
The breakthrough clue in the KimWolf investigation came when a Big Pipes employee's $50 digital picture frame was found to be launching DDoS attacks.
Chapter 12 · 26:30
A brief sponsored segment from Intuit promotes the Intuit Enterprise Suite, described as a powerful, painless, and proven AI-native ERP solution for finance teams dealing with fragmented data sources and the challenges of business scaling.
Ben Brundage installed IP Idea's software on an old Android phone via a pirated streaming app and monitored all traffic coming in and out. Within a week, a mysterious domain appeared: xd.resi.to — the direct link KimWolf was using to break into devices on the network.
Chapter 13 · 26:38
Ben's big insight was simple but brilliant: if you want to catch something exploiting residential proxy devices, become one [1] — Benjamin Brundage "Ben Brundage installed IP Idea's software on an old Android phone via a pirated streaming app and monitored all traffic coming in and out. …" 26:30 . He installed IP Idea's software on a spare Android phone, downloaded from a website offering pirated streaming content, and built a monitoring setup to capture every byte of traffic coming in and out. Then he waited — balancing the experiment with studying for midterms. Within a week, one domain kept appearing in the traffic logs: xd.resi.to, an address with no obvious connection to IP Idea. Ben immediately flagged it. The domain turned out to be KimWolf's foothold: it was using the residential proxy's own access to the device to pivot from the open internet into the phone's local network — and from there, commandeer the device entirely. As Robert McMillan put it, it was like an Airbnb guest deciding to squat in the rental and rummage through all the locked closets. Ben brought his findings to Big Pipes, and together they confirmed that KimWolf had exploited a bug in IP Idea's own code to pull off this attack at scale.
KimWolf exploited a bug in IP Idea's residential proxy code to break into home networks and install DDoS malware on consumer devices. It was like an Airbnb guest deciding to squat in the rental and rummage through all the locked closets.
Chapter 14 · 30:55
With the exploit understood, Ben moved to warn the industry. He identified 10 other residential proxy companies vulnerable to the same bug IP Idea had [1] — Jessica Mendoza "Bug found in 11 proxy companies: Ben Brundage discovered that not only IP Idea but 10 other residential proxy companies were also vulnerabl…" 31:15 . As his final exams loomed, he drafted notifications to all of them, sending the emails on December 17th — the day after his last test [2] — Jessica Mendoza "10 million pre-installed devices: Google identified more than 10 million devices that came with IP Idea's software secretly pre-installed o…" 32:50 . IP Idea replied 9 days later, claiming the email had gone to spam and promising a fix. It was too little, too late. In January, Google obtained a US court order and moved decisively: 13 of IP Idea's business domains were taken down and dozens of its servers were shut off. Google had by then identified over 10 million devices pre-installed with IP Idea's software. Two months later, in March, the Department of Justice struck against four of the world's largest DDoS botnets, including KimWolf — seizing domains, virtual servers, and network infrastructure. At the end of the DOJ press release was a list of companies thanked for their help. Among the major tech firms was Synthient: Ben's one-man startup, operating out of a college dorm room.
Ben Brundage discovered that not only IP Idea but 10 other residential proxy companies were also vulnerable to the same bug exploited by KimWolf.
In January, Google obtained a US court order to shut down 13 of IP Idea's business domains and dozens of its servers. Two months later, the DOJ struck against four major DDoS botnets including KimWolf, seizing domains and infrastructure — and thanked Ben's startup Synthient in the press release.
Google identified more than 10 million devices that came with IP Idea's software secretly pre-installed on them.
According to DOJ court filings, KimWolf launched more than 26,000 DDoS attacks targeting over 8,000 victims worldwide.
Two months after Google's action, the DOJ struck against four of the world's largest DDoS botnets, including KimWolf, seizing domains, servers, and network infrastructure.
Despite the DOJ and Google takedowns, cybersecurity experts say KimWolf is still active, lurking in thousands of vulnerable consumer devices.
Chapter 15 · 34:25
Despite the Google and DOJ actions, KimWolf hasn't been fully exterminated — it still lurks in thousands of compromised devices, a reminder that botnets are stubbornly resilient. Robert McMillan frames the lasting lesson with characteristic bluntness: the internet is full of junk [1] — Robert McMillan "The real takeaway here is that we have an internet filled with junk. We have garbage devices, garbage apps that are doing a lot of bad stuf…" 34:26 . Garbage devices and garbage apps have quietly become part of the criminal infrastructure, and the problem — what he calls 'internet pollution' — has no clear solution yet. For listeners who want to know if their own network is secretly enrolled in a residential proxy, Bob has written a guide available in the show notes. As for Ben Brundage, the unlikely hero of the whole story, he's now focused on finishing his degree, growing Synthient, and maybe taking his first real vacation in a long time. And if the rumors he's heard are true, there might be a t-shirt in his future — one that says, 'I stopped KimWolf, and all I got was this lousy t-shirt.'
The lasting lesson of KimWolf isn't just about one botnet — it's that the internet is flooded with garbage devices and apps that have become part of criminal infrastructure. Robert McMillan calls it 'internet pollution,' and nobody has figured out how to clean it up.
No indexed bits in this chapter.
This episode
Factual claims made this episode, and whether a source was named.
KimWolf quietly hijacked nearly 2 million Android devices across the globe.
KimWolf launched more than 26,000 DDoS attacks targeting over 8,000 victims, according to DOJ court filings.
Google identified more than 10 million devices that came with IP Idea's software secretly pre-installed.
The KimWolf hacker told Benjamin Brundage that the operation was spending $30,000 a month on infrastructure.
One KimWolf DDoS attack was so large it was as if everyone in Germany, Spain, and the UK had visited the same website at the exact same second.
In January, Google used a US court order to take down 13 of IP Idea's business domains and shut down dozens of its servers.
The Department of Justice took action against four of the world's largest DDoS botnets, including KimWolf, by seizing internet domains, virtual servers, and other network infrastructure.
IP Idea appeared to operate under more than a dozen different brand names and listed no CEO, founder, or address on its websites.
Ben Brundage found two major security vulnerabilities in Dutch government websites during a public bug-bounty program while still in high school.
Ben Brundage identified around 2 million devices — including TV boxes, phones, cameras, and picture frames — that had been hacked by KimWolf.
IP Idea's fix to the exploited bug came too late: the company replied to Ben's notification 9 days after it was sent, claiming his email went to spam.
The DOJ's press release on the KimWolf takedown thanked Google, Lumen, and Synthient by name for their contributions.
This episode
22-year-old college senior who independently mapped KimWolf's infrastructure, built a honeypot to expose the exploit, and was credited by the DOJ for helping dismantle the botnet.
WSJ cybersecurity reporter who covered the KimWolf story and contributed expert commentary throughout the episode.
Lumen engineer who was researching residential proxy threats, connected with Benjamin Brundage, and credited him as the MVP of the KimWolf investigation.
A shadowy residential proxy company operating under 12+ brand names whose unsecured network was exploited by KimWolf to hijack millions of consumer devices.
An elite cybersecurity working group made up of engineers from major internet companies, coordinating the investigation and takedown of KimWolf.
A networking company whose engineer Chris Formosa was researching residential proxy threats and connected Benjamin Brundage to the Big Pipes working group.
Took legal action against four major DDoS botnets including KimWolf, seizing domains and servers, and publicly thanked Synthient in its press release.
Used a US court order to take down 13 of IP Idea's business domains and dozens of its servers, identifying over 10 million pre-infected devices.
Co-producer of The Journal podcast; also mentioned as the platform whose stolen Premium accounts Ben Brundage saw shared in a hacking community, prompting him to warn the victims.
Benjamin Brundage's one-man cybersecurity startup, credited by the DOJ in their press release for contributing to the KimWolf takedown.
The university in upstate New York where Benjamin Brundage was studying computer science when he uncovered and helped dismantle KimWolf.
The world's largest observed botnet, hijacking ~2 million devices to launch massive DDoS attacks until taken down by Google and the DOJ.
A messaging app popular with gamers where Benjamin Brundage encountered hacking communities and later corresponded with a KimWolf-connected hacker.
The open-world video game that first sparked Benjamin Brundage's interest in coding and modding, serving as the gateway to his cybersecurity career.
Stats
We use essential and analytics cookies to run Vuci. To understand how the site is used: Privacy Policy.
Install Vuci on your phone
Add it to your home screen for a faster, app-like experience.
Install Vuci on your phone
Tap the Share button, then “Add to Home Screen”.
A new version is available
Reload to get the latest Vuci.