Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Researchers uncovered Kimwolf v7, a new version of the Kimwolf/AISURU Android and IoT botnet that adds browser-like HTTP/2 DDoS flooding and more resilient command-and-control infrastructure. The malware now relies on Ethereum Name Service, a hard-coded Tor hidden service, and a local proxy while shifting propagation duties to an external loader and targeting Android TV boxes via ADB. #Kimwolf #AISURU #Unit42 #EthereumNameService #ADB

Keypoints

  • Kimwolf v7 adds HTTP/2 DDoS flooding with full browser fingerprints.
  • Its C2 infrastructure now uses ENS, Tor, and a local proxy for resilience.
  • Scanning, exploitation, and brute-force modules were removed from the binary.
  • The botnet targets Android TV boxes and Linux IoT devices through ADB abuse.
  • Unit 42 found APKs posing as SystemService and using bundled ELF payloads.

Read More: https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html