Kimwolf botnet rebuilt to survive takedowns, researchers say

Kimwolf botnet rebuilt to survive takedowns, researchers say
Palo Alto Networks’ Unit 42 says the Kimwolf, or Aisuru, botnet has added an HTTP/2-based flood method that uses Chrome-like browser fingerprints to make DDoS traffic look like normal web browsing. The latest version also shifts command-and-control lookups to Ethereum Name Service and Tor to resist takedowns after prior infrastructure seizures and arrests. #Kimwolf #Aisuru #Unit42 #EthereumNameService #Tor

Keypoints

  • Kimwolf, also tracked as Aisuru, now uses an HTTP/2 flood designed to blend in with normal browser traffic.
  • The botnet copies Chrome header order and behavior to bypass common DDoS filtering.
  • Its command-and-control addresses are now resolved through Ethereum Name Service instead of standard domain records.
  • If ENS lookups fail, the malware falls back to a hardcoded Tor hidden service.
  • Researchers linked the command infrastructure to servers in Russia, while the botnet remains tied to earlier law enforcement seizures and arrests.

Read More: https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/