radar.cysentrix
3 reports · 3 sources · tracked since 5d ago

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

AI synthesis Researchers detailed Kimwolf v7, an Android/IoT botnet upgrade that disguises HTTP/2 DDoS traffic as legitimate browsing, adds Ethereum ENS-based C2 resolution, and Tor backup routing for stronger resilience.

malware
Why this ranks Transparent score: 17
coverage +9 source breadth +6 urgency +0 freshness +2

What changed

Coverage timeline

Every report remains linked to its original publisher.

  1. Unit 42 First observed

    Kimwolf v7: An Evolution of the Kimwolf Botnet ↗

    Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

  2. The Hacker News Coverage expanded

    Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing ↗

    Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, t...

  3. Security Affairs Coverage expanded

    Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum ↗

    Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while hunting threats following public disclosures of the botnet’s earlier activity. The new version subst...