Researchers uncovered Kimwolf v7, a new version of the Kimwolf/AISURU Android and IoT botnet that adds browser-like HTTP/2 DDoS flooding and more resilient command-and-control infrastructure. The malware now relies on Ethereum Name Service, a hard-coded Tor hidden service, and a local proxy while shifting propagation duties to an external loader and targeting Android TV boxes via ADB. #Kimwolf #AISURU #Unit42 #EthereumNameService #ADB
Keypoints
- Kimwolf v7 adds HTTP/2 DDoS flooding with full browser fingerprints.
- Its C2 infrastructure now uses ENS, Tor, and a local proxy for resilience.
- Scanning, exploitation, and brute-force modules were removed from the binary.
- The botnet targets Android TV boxes and Linux IoT devices through ADB abuse.
- Unit 42 found APKs posing as SystemService and using bundled ELF payloads.
Read More: https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html