Kimwolf v7 Botnet Enhances DDoS Capabilities with HTTP/2 Traffic Mimicking Legitimate Browsing

Published:

spot_img

New Kimwolf v7 Botnet Enhances DDoS Capabilities

Cybersecurity researchers have identified a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet, known as Kimwolf v7, which features significant enhancements aimed at improving its operational resilience and executing distributed denial-of-service (DDoS) attacks. Discovered by Palo Alto Networks Unit 42 in February 2026, this version introduces an HTTP/2-based DDoS flood that creates complete browser fingerprints, making it challenging to differentiate attack traffic from legitimate browsing.

According to reporting by The Hacker News, the botnet’s command-and-control (C2) infrastructure has been fortified against takedown efforts through a tiered mechanism that utilizes the Ethereum Name Service (ENS) for C2 address acquisition, a hard-coded Tor .onion hidden service, and a local proxy for routing traffic between clearnet and Tor. Notably, all scanning, exploitation, and brute-force functionalities have been removed, indicating a strategic shift in the botnet’s operational model.

Targeting Android Devices

Active since at least mid-2024, Kimwolf primarily targets Android TV boxes, leveraging residential proxy services to access devices with Android Debug Bridge (ADB) enabled on local networks. Once installed, the malware disguises itself as legitimate Android system processes, such as “netd_service,” to evade detection. The new version includes several advanced features:

  • HTTP/2 flood attacks powered by the nghttp2 library, mimicking Google Chrome browser behavior at the protocol and header level.
  • Utilization of legitimate public Ethereum RPC services to resolve C2 addresses.
  • A backup C2 mechanism via a hard-coded Tor .onion hidden service.
  • A local proxy architecture that routes all C2 traffic through 127.0.0.1:23075.
  • A high-performance UDP flood function targeting ARM processors in Android TV boxes.
  • Consolidation of DDoS attack commands to 15 numbered methods, down from 43 in previous versions.

Operational Security Adjustments

The Kimwolf operators have also been observed distributing Android APK packages that masquerade as a system service called SystemService, which probe for root access and execute a bundled ELF kernel payload. This evolution suggests a shift from traditional Linux exploitation methods to an ADB-based propagation model for Android devices.

Unit 42 emphasizes that organizations should treat Android TV boxes as untrusted devices and segment them from enterprise networks. Disabling ADB or restricting it to USB-only access can mitigate the primary propagation vector for this botnet.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

Jaguar Land Rover Faces Sales Decline Amid Middle East Disruptions and Supplier Fire

Jaguar Land Rover (JLR) is grappling with a significant decline in sales, attributed to disruptions stemming from the ongoing conflict in the Middle East...

Twenty-one cybersecurity mergers and acquisitions announced in July 2026

Twenty-one cybersecurity-related merger and acquisition (M&A) deals were announced in July 2026. According to reporting by SecurityWeek, these transactions reflect ongoing consolidation in the cybersecurity...

Ransomware Landscape Shifts as Active Groups Rise and Payment Rates Decline in Q2 2026

The ransomware landscape is undergoing a notable transformation, as highlighted in the latest State of Ransomware Q2 2026 report from Check Point Research. While...

AMD Security Advisory AV26-813 Warns of Vulnerabilities in Multiple Products

AMD Security Advisory AV26-813: Vulnerabilities Identified in Multiple Products On August 11, 2026, AMD disclosed vulnerabilities affecting several of its products, as detailed in the...