[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFTxrTCgYXTGEfSamgP1g0VcUYUqiJahVRySh0MT-WGo":3},{"article":4,"iocs":46},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"f072e46d-c74c-494f-8af1-278c3a5b8779","Kimwolf v7 Android Botnet Makes HTTP\u002F2 DDoS Traffic Look Like Legitimate Browsing","kimwolf-v7-android-botnet-makes-http-2-ddos-traffic-look-like-legitimate-browsin-04af50","Cybersecurity researchers have discovered a new version of the Kimwolf\u002FAISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. \"Kimwolf v7 adds an HTTP\u002F2-based","The Kimwolf v7 Android and IoT botnet has been updated with enhanced resilience and improved DDoS attack capabilities. This new version uses HTTP\u002F2 to mimic legitimate browser traffic, making its attacks harder to detect. It also employs a tiered C2 infrastructure using Ethereum Name Service (ENS) and Tor to resist takedowns.","Kimwolf v7 Android botnet evolves with HTTP\u002F2 DDoS, ENS C2, and Tor.","Kimwolf v7 Android Botnet Makes HTTP\u002F2 DDoS Traffic Look Like Legitimate Browsing Ravie LakshmananAug 11, 2026Botnet \u002F Vulnerability Cybersecurity researchers have discovered a new version of the Kimwolf\u002FAISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. \"Kimwolf v7 adds an HTTP\u002F2-based DDoS flood that constructs complete browser fingerprints,\" researchers Asher Davila, Chris Navarrete, and Doel Santos said. \"This makes attack traffic more difficult to distinguish from legitimate browsing.\" The botnet also aims to make its command-and-control (C2) infrastructure more resistant to takedown efforts by using a tiered mechanism that employs Ethereum Name Service (ENS) to obtain the C2 address, a hard-coded Tor .onion hidden service, and a local proxy for routing between clearnet and Tor, while removing all scanning, exploitation, and brute-force functionality. The removal of the scanner and exploit modules is an indication that the threat actors behind the operation have split the propagation pipeline from the core payload, offloading the task to an external loader for initial access, while the Kimwolf binary handles DDoS attacks and proxy relay. Kimwolf is known to target Android TV boxes since August 2025, while its Linux counterpart, AISURU, primarily focuses on Linux IoT devices. The botnet has been active since at least mid-2024. The botnet typically abuses residential proxy services to reach Android TVs that ship with Android Debug Bridge (ADB) enabled on port 5555 on local networks and install malware capable of conducting DDoS attacks and acting as a relay to ferry malicious traffic. Once launched, the malware attempts to mask itself as seemingly legitimate Android system processes (e.g., \"netd_service\") to fly under the radar. Some of the newly observed features in the new version are as follows - Carry out HTTP\u002F2 flood attacks powered by the nghttp2 library along with constructing complete browser fingerprints that mirror legitimate browser behavior at the protocol and header level Using legitimate public Ethereum RPC services to query ENS domain records and resolve C2 addresses A backup C2 mechanism that uses a Tor .onion hidden service (\"edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd[.]onion\") that's hard-coded into the binary A local proxy architecture that routes all C2 traffic through 127.0.0[.]1:23075, irrespective of whether it's headed to clearnet or Tor A high-performance UDP flood function that specifically targets ARM processors found in Android TV boxes Consolidate all DDoS attack commands to 15 numbered methods, down from 43 text-named methods found in prior versions The Kimwolf operators have also been found to distribute Android APK packages that masquerade as a system service called SystemService, probe for root access, and execute a bundled ELF kernel payload inside. Eight such APK artifacts have been identified between October and December 2025. \"The earliest dropped sample, targeting the x86 architecture with a Dirty COW exploit, suggests the family evolved from traditional Linux exploitation toward the current ADB-based Android propagation model,\" Unit 42 said. \"The transition from libn[redacted]kernel.so to the less conspicuous libdevice.so filename in November 2025, followed by a revert in December, indicates active operational security adjustments.\" The disclosure comes as a number of new botnet malware families have been detected in recent months - AryStinger, which enlists older, vulnerable home routers into a network for distributed reconnaissance and proxying RustDuck, which hijacks home routers, IP cameras, Android boxes, and poorly secured servers to rope them into a network for conducting DDoS attacks NadMesh, which combines scanning, exploitation, and credential\u002FAI-service intelligence harvesting into a single autonomous platform that's designed to scan for Redis, Docker, MCP, Kubernetes, ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances, drop an SSH backdoor, and harvest credentials, environment variables, account tokens, and AWS and Docker configurations Tengu, a Mirai-derived IoT malware that employs Telnet brute-force to hijack IoT devices and run instructions that allow it to launch DoS attacks, gather network configuration information, set up persistence, exfiltrate system metadata, execute commands, download additional payloads, and turn the infected node into a proxy. \"Kimwolf v7 is a focused evolution of an already large-scale botnet,\" Unit 42 said. \"Organizations should treat Android TV boxes as untrusted and segment them from enterprise networks. Disabling ADB or restricting it to USB-only access removes the primary propagation vector for this botnet.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Android security, botnet, Cyber Attack, ddos attack, iot security, Linux security, Malware, network security, Threat Intelligence, Vulnerability ⚡ Top Stories This Week Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fkimwolf-v7-android-botnet-makes-http2.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEieGDZmdQhY70KqvppH4w5wMVhbs804WeageCN1UXtRK4KpFkYWNk-wkTeTv9CUSNGYQMsaZ04XYWimXsIQmfl0uYSFgNJe7uBbXsg1xPw-cukXwJY3O3TAHUpWiiYmleWgDpu4PLMRfjgIQtOxb6Wq2yFjvqyb6lpoCOcOyWOpZoURLpddzyGkmc8soRHe\u002Fs1600\u002Fandroid-botnet.jpg","2026-08-11T19:36:37+00:00","2026-08-11T22:00:17.283153+00:00",8,[18,21,24,26],{"name":19,"type":20},"Palo Alto Networks","vendor",{"name":22,"type":23},"HTTP\u002F2","technology",{"name":25,"type":23},"Ethereum Name Service",{"name":27,"type":23},"Tor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":28,"icon":30,"name":31,"slug":32},null,"Malware","malware",[34,36,41],{"category":35},{"id":28,"icon":30,"name":31,"slug":32},{"category":37},{"id":38,"icon":30,"name":39,"slug":40},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":42},{"id":43,"icon":30,"name":44,"slug":45},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[47],{"type":48,"value":49,"context":50},"domain","edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd.onion","Hard-coded Tor .onion hidden service for C2 communication."]