Kimwolf botnet evolves to mimic browsers with HTTP/2 flood attacks

Unit 42 documents Kimwolf v7, a rebuild that hides DDoS floods behind browser fingerprints and Ethereum domains.

CSBadmin
2 Min Read

Palo Alto Networks Unit 42 has published an analysis of Kimwolf v7, a rebuilt version of the Android and IoT botnet that makes its attack traffic look like ordinary web browsing. Researchers spotted the new iteration in February 2026.

The headline change is an HTTP/2-based DDoS flood that builds complete browser fingerprints, matching legitimate browsers at the protocol and header level. Traffic generated with the nghttp2 library no longer carries the telltale marks of a malformed flood.

Command and control got the same hardening treatment. C2 addresses now come from the Ethereum Name Service. A hard-coded Tor .onion hidden service stands by as backup, and a local proxy carries all C2 traffic whether it heads to the clearnet or Tor. The command set shrank too, from 43 text-named DDoS methods down to 15 numbered ones.

The most striking shift: scanning, exploitation, and brute-force modules are gone. Unit 42 says the operators split propagation from the core payload, handing initial access to an external loader while the Kimwolf binary focuses on DDoS and proxy relay.

Kimwolf reaches Android TV boxes that ship with Android Debug Bridge enabled on port 5555, often through residential proxies, then installs malware that impersonates system processes. Some Android payloads masquerade as a service called SystemService and probe for root access.

The researchers’ guidance is blunt: treat Android TV boxes as untrusted and keep them off enterprise networks. Switching off ADB, or restricting it to USB-only, strips the botnet of its primary way in.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.