Cybersecurity researchers have uncovered Kimwolf v7, an updated version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet. This new iteration, identified by Palo Alto Networks Unit 42 in February 2026, includes significant enhancements aimed at improving its operational resilience and the effectiveness of its distributed denial-of-service (DDoS) attacks.
Kimwolf v7 introduces an HTTP/2-based DDoS flood mechanism that constructs complete browser fingerprints. This technique makes the botnet's attack traffic difficult to distinguish from legitimate web browsing, complicating detection and mitigation efforts. The botnet leverages the nghttp2 library for these HTTP/2 flood attacks, mirroring legitimate browser behavior at both protocol and header levels.
The new version also focuses on making its command-and-control (C2) infrastructure more resistant to takedowns. It utilizes a tiered mechanism that includes Ethereum Name Service (ENS) to resolve C2 addresses, a hard-coded Tor .onion hidden service for backup, and a local proxy for routing traffic between clearnet and Tor. This multi-layered approach aims to ensure continuous operation even if parts of its C2 infrastructure are compromised.
Kimwolf v7 has removed all scanning, exploitation, and brute-force functionality from its core binary. This indicates a shift where threat actors have separated the propagation pipeline from the core payload, offloading initial access to an external loader. The Kimwolf binary now primarily handles DDoS attacks and acts as a proxy relay. The botnet has been active since at least mid-2024, targeting Android TV boxes since August 2025 and Linux IoT devices through its AISURU counterpart. It typically abuses residential proxy services to reach Android TVs with Android Debug Bridge (ADB) enabled on local networks, installing malware that masks itself as legitimate Android system processes.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cybersecurity researchers have identified Kimwolf v7, a new version of the Android and IoT botnet, which now employs HTTP/2 DDoS attacks that mimic legitimate browser traffic and uses Ethereum Name Service (ENS) for more resilient command-and-control (C2) infrastructure. This development makes the botnet's attacks harder to detect and its C2 more difficult to disrupt, posing an increased threat to Android TV boxes and Linux IoT devices.