Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

The Hacker News by The Hacker News
August 11, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananAug 11, 2026Botnet / Vulnerability

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks.

The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026.

“Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints,” researchers Asher Davila, Chris Navarrete, and Doel Santos said. “This makes attack traffic more difficult to distinguish from legitimate browsing.”

The botnet also aims to make its command-and-control (C2) infrastructure more resistant to takedown efforts by using a tiered mechanism that employs Ethereum Name Service (ENS) to obtain the C2 address, a hard-coded Tor .onion hidden service, and a local proxy for routing between clearnet and Tor, while removing all scanning, exploitation, and brute-force functionality.

The removal of the scanner and exploit modules is an indication that the threat actors behind the operation have split the propagation pipeline from the core payload, offloading the task to an external loader for initial access, while the Kimwolf binary handles DDoS attacks and proxy relay.

Kimwolf is known to target Android TV boxes since August 2025, while its Linux counterpart, AISURU, primarily focuses on Linux IoT devices. The botnet has been active since at least mid-2024.

The botnet typically abuses residential proxy services to reach Android TVs that ship with Android Debug Bridge (ADB) enabled on port 5555 on local networks and install malware capable of conducting DDoS attacks and acting as a relay to ferry malicious traffic.

Once launched, the malware attempts to mask itself as seemingly legitimate Android system processes (e.g., “netd_service”) to fly under the radar. Some of the newly observed features in the new version are as follows –

  • Carry out HTTP/2 flood attacks powered by the nghttp2 library along with constructing complete browser fingerprints that mirror legitimate browser behavior at the protocol and header level
  • Using legitimate public Ethereum RPC services to query ENS domain records and resolve C2 addresses
  • A backup C2 mechanism that uses a Tor .onion hidden service (“edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd[.]onion”) that’s hard-coded into the binary
  • A local proxy architecture that routes all C2 traffic through 127.0.0[.]1:23075, irrespective of whether it’s headed to clearnet or Tor
  • A high-performance UDP flood function that specifically targets ARM processors found in Android TV boxes
  • Consolidate all DDoS attack commands to 15 numbered methods, down from 43 text-named methods found in prior versions

The Kimwolf operators have also been found to distribute Android APK packages that masquerade as a system service called SystemService, probe for root access, and execute a bundled ELF kernel payload inside. Eight such APK artifacts have been identified between October and December 2025.

“The earliest dropped sample, targeting the x86 architecture with a Dirty COW exploit, suggests the family evolved from traditional Linux exploitation toward the current ADB-based Android propagation model,” Unit 42 said. “The transition from libn[redacted]kernel.so to the less conspicuous libdevice.so filename in November 2025, followed by a revert in December, indicates active operational security adjustments.”

The disclosure comes as a number of new botnet malware families have been detected in recent months –

  • AryStinger, which enlists older, vulnerable home routers into a network for distributed reconnaissance and proxying
  • RustDuck, which hijacks home routers, IP cameras, Android boxes, and poorly secured servers to rope them into a network for conducting DDoS attacks
  • NadMesh, which combines scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform that’s designed to scan for Redis, Docker, MCP, Kubernetes, ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances, drop an SSH backdoor, and harvest credentials, environment variables, account tokens, and AWS and Docker configurations
  • Tengu, a Mirai-derived IoT malware that employs Telnet brute-force to hijack IoT devices and run instructions that allow it to launch DoS attacks, gather network configuration information, set up persistence, exfiltrate system metadata, execute commands, download additional payloads, and turn the infected node into a proxy.

“Kimwolf v7 is a focused evolution of an already large-scale botnet,” Unit 42 said. “Organizations should treat Android TV boxes as untrusted and segment them from enterprise networks. Disabling ADB or restricting it to USB-only access removes the primary propagation vector for this botnet.”



Source link

The Hacker News

The Hacker News

Next Post
CEOs eye job cuts as AI adoption grows

CEOs eye job cuts as AI adoption grows

Recommended.

Meta Is in Crisis, Google Search’s Makeover, and AI Gets Booed by Graduates

Meta Is in Crisis, Google Search’s Makeover, and AI Gets Booed by Graduates

May 21, 2026
MindArk Launches AI-Powered Global Localisation for Entropia Universe

MindArk Launches AI-Powered Global Localisation for Entropia Universe

June 10, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio