Palo Alto Networks’ Unit 42 says the Kimwolf, or Aisuru, botnet has added an HTTP/2-based flood method that uses Chrome-like browser fingerprints to make DDoS traffic look like normal web browsing. The latest version also shifts command-and-control lookups to Ethereum Name Service and Tor to resist takedowns after prior infrastructure seizures and arrests. #Kimwolf #Aisuru #Unit42 #EthereumNameService #Tor
Keypoints
- Kimwolf, also tracked as Aisuru, now uses an HTTP/2 flood designed to blend in with normal browser traffic.
- The botnet copies Chrome header order and behavior to bypass common DDoS filtering.
- Its command-and-control addresses are now resolved through Ethereum Name Service instead of standard domain records.
- If ENS lookups fail, the malware falls back to a hardcoded Tor hidden service.
- Researchers linked the command infrastructure to servers in Russia, while the botnet remains tied to earlier law enforcement seizures and arrests.
Read More: https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/