New Kimwolf v7 Botnet Enhances DDoS Capabilities
Cybersecurity researchers have identified a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet, known as Kimwolf v7, which features significant enhancements aimed at improving its operational resilience and executing distributed denial-of-service (DDoS) attacks. Discovered by Palo Alto Networks Unit 42 in February 2026, this version introduces an HTTP/2-based DDoS flood that creates complete browser fingerprints, making it challenging to differentiate attack traffic from legitimate browsing.
According to reporting by The Hacker News, the botnet’s command-and-control (C2) infrastructure has been fortified against takedown efforts through a tiered mechanism that utilizes the Ethereum Name Service (ENS) for C2 address acquisition, a hard-coded Tor .onion hidden service, and a local proxy for routing traffic between clearnet and Tor. Notably, all scanning, exploitation, and brute-force functionalities have been removed, indicating a strategic shift in the botnet’s operational model.
Targeting Android Devices
Active since at least mid-2024, Kimwolf primarily targets Android TV boxes, leveraging residential proxy services to access devices with Android Debug Bridge (ADB) enabled on local networks. Once installed, the malware disguises itself as legitimate Android system processes, such as “netd_service,” to evade detection. The new version includes several advanced features:
- HTTP/2 flood attacks powered by the nghttp2 library, mimicking Google Chrome browser behavior at the protocol and header level.
- Utilization of legitimate public Ethereum RPC services to resolve C2 addresses.
- A backup C2 mechanism via a hard-coded Tor .onion hidden service.
- A local proxy architecture that routes all C2 traffic through 127.0.0.1:23075.
- A high-performance UDP flood function targeting ARM processors in Android TV boxes.
- Consolidation of DDoS attack commands to 15 numbered methods, down from 43 in previous versions.
Operational Security Adjustments
The Kimwolf operators have also been observed distributing Android APK packages that masquerade as a system service called SystemService, which probe for root access and execute a bundled ELF kernel payload. This evolution suggests a shift from traditional Linux exploitation methods to an ADB-based propagation model for Android devices.
Unit 42 emphasizes that organizations should treat Android TV boxes as untrusted devices and segment them from enterprise networks. Disabling ADB or restricting it to USB-only access can mitigate the primary propagation vector for this botnet.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


