CyberNews
← Back to dashboard
NEWS The Hacker News

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing - The Hacker News

Aug 11, 2026, 07:36 PM · by The Hacker News

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks.

The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026.

"Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints," researchers Asher Davila, Chris Navarrete, and Doel Santos said. "This makes attack traffic more difficult to distinguish from legitimate browsing."

The botnet also aims to make its command-and-control (C2) infrastructure more resistant to takedown efforts by using a tiered mechanism that employs Ethereum Name Service (ENS) to obtain the C2 address, a hard-coded Tor .onion hidden service, and a local proxy for routing between clearnet and Tor, while removing all scanning, exploitation, and brute-force functionality.

Source: The Hacker News