← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Kimwolf v7 Android Botnet Uses HTTP/2 DDoS with Browser Fingerprints, Enhances C2 Resilience

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Kimwolf v7 uses HTTP/2 DDoS attacks with full browser fingerprints.
  • The botnet employs ENS and Tor .onion for C2 resilience.
  • Scanning and exploitation modules are removed from the core binary.
  • Targets Android TV boxes and Linux IoT devices, active since mid-2024.

New Kimwolf Botnet Version Discovered

Cybersecurity researchers have uncovered Kimwolf v7, an updated version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet. This new iteration, identified by Palo Alto Networks Unit 42 in February 2026, includes significant enhancements aimed at improving its operational resilience and the effectiveness of its distributed denial-of-service (DDoS) attacks.

Advanced DDoS Capabilities

Kimwolf v7 introduces an HTTP/2-based DDoS flood mechanism that constructs complete browser fingerprints. This technique makes the botnet's attack traffic difficult to distinguish from legitimate web browsing, complicating detection and mitigation efforts. The botnet leverages the nghttp2 library for these HTTP/2 flood attacks, mirroring legitimate browser behavior at both protocol and header levels.

Enhanced Command-and-Control Resilience

The new version also focuses on making its command-and-control (C2) infrastructure more resistant to takedowns. It utilizes a tiered mechanism that includes Ethereum Name Service (ENS) to resolve C2 addresses, a hard-coded Tor .onion hidden service for backup, and a local proxy for routing traffic between clearnet and Tor. This multi-layered approach aims to ensure continuous operation even if parts of its C2 infrastructure are compromised.

Operational Changes and Targets

Kimwolf v7 has removed all scanning, exploitation, and brute-force functionality from its core binary. This indicates a shift where threat actors have separated the propagation pipeline from the core payload, offloading initial access to an external loader. The Kimwolf binary now primarily handles DDoS attacks and acts as a proxy relay. The botnet has been active since at least mid-2024, targeting Android TV boxes since August 2025 and Linux IoT devices through its AISURU counterpart. It typically abuses residential proxy services to reach Android TVs with Android Debug Bridge (ADB) enabled on local networks, installing malware that masks itself as legitimate Android system processes.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers have identified Kimwolf v7, a new version of the Android and IoT botnet, which now employs HTTP/2 DDoS attacks that mimic legitimate browser traffic and uses Ethereum Name Service (ENS) for more resilient command-and-control (C2) infrastructure. This development makes the botnet's attacks harder to detect and its C2 more difficult to disrupt, posing an increased threat to Android TV boxes and Linux IoT devices.