Palo Alto Networks: Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Palo Alto Networks: Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Kimwolf v7 Botnet Enhances DDoS Capabilities with Stealth and Resilience

Cybersecurity researchers at Palo Alto Networks’ Unit 42 have uncovered a significant upgrade to the Kimwolf/AISURU botnet, now tracked as Kimwolf v7, which introduces advanced evasion techniques and improved infrastructure resilience. Discovered in February 2026, the new variant targets Android TV boxes and Linux IoT devices, refining its methods for distributed denial-of-service (DDoS) attacks while making detection and takedown efforts more difficult.

Key Enhancements in Kimwolf v7

The latest version introduces an HTTP/2-based DDoS flood attack that mimics legitimate browser traffic by generating complete browser fingerprints, complicating differentiation between malicious and benign requests. The botnet also strengthens its command-and-control (C2) infrastructure through a tiered system:

  • Ethereum Name Service (ENS) for dynamic C2 address resolution via public Ethereum RPC services.
  • A hard-coded Tor .onion hidden service (edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd.onion) as a backup.
  • A local proxy (127.0.0.1:23075) to route traffic between clearnet and Tor, obscuring communication.

Notably, Kimwolf v7 removes built-in scanning and exploitation modules, instead relying on an external loader for initial access. This separation suggests a shift toward modular malware deployment, where the core binary focuses solely on DDoS attacks and proxy relaying.

Targeting and Infection Methods

Kimwolf has been active since mid-2024, with a focus on Android TV boxes since August 2025. The botnet exploits devices with Android Debug Bridge (ADB) enabled on port 5555, often leveraging residential proxy services to infiltrate local networks. Once installed, the malware masquerades as legitimate system processes (e.g., netd_service) to evade detection.

Additional technical improvements include:

  • High-performance UDP flood attacks optimized for ARM processors in Android TV boxes.
  • Consolidated DDoS attack commands (15 numbered methods, down from 43 in prior versions).
  • APK-based distribution disguised as a system service (SystemService), with eight identified samples between October and December 2025.
  • Evolutionary traces from Linux exploitation (e.g., Dirty COW exploit) to the current ADB-based propagation model, with ongoing operational security adjustments (e.g., filename changes from libn[redacted]kernel.so to libdevice.so).

Broader Botnet Landscape

The discovery of Kimwolf v7 coincides with the emergence of other new botnet families, including:

  • AryStinger: Hijacks vulnerable home routers for distributed reconnaissance and proxying.
  • RustDuck: Compromises routers, IP cameras, and Android boxes for DDoS attacks.
  • NadMesh: An autonomous platform scanning for Redis, Docker, Kubernetes, and AI services, harvesting credentials, tokens, and configurations while deploying SSH backdoors.
  • Tengu: A Mirai-derived IoT malware using Telnet brute-forcing to launch DoS attacks, exfiltrate data, and establish persistence.

Kimwolf v7 represents a focused evolution of an already large-scale botnet, underscoring the growing sophistication of IoT and Android-based threats. Its reliance on ADB exploitation and stealthy C2 mechanisms highlights the need for heightened vigilance in securing consumer-grade devices.

Source: https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html

Palo Alto Networks cybersecurity rating report: https://www.rankiteo.com/company/palo-alto-networks

"id": "PAL1786479836",
"linkid": "palo-alto-networks",
"type": "Cyber Attack",
"date": "2/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Technology, IoT',
                        'type': 'Consumer devices'}],
 'attack_vector': ['Android Debug Bridge (ADB) exploitation on port 5555',
                   'APK-based distribution disguised as system service'],
 'date_detected': '2026-02',
 'description': 'Cybersecurity researchers at Palo Alto Networks’ Unit 42 have '
                'uncovered a significant upgrade to the Kimwolf/AISURU botnet, '
                'now tracked as Kimwolf v7, which introduces advanced evasion '
                'techniques and improved infrastructure resilience. The new '
                'variant targets Android TV boxes and Linux IoT devices, '
                'refining its methods for distributed denial-of-service (DDoS) '
                'attacks while making detection and takedown efforts more '
                'difficult.',
 'impact': {'operational_impact': 'DDoS attacks causing service disruptions',
            'systems_affected': ['Android TV boxes', 'Linux IoT devices']},
 'initial_access_broker': {'entry_point': 'ADB exploitation, APK-based '
                                          'distribution'},
 'investigation_status': 'Ongoing',
 'motivation': ['DDoS attacks', 'Proxy relaying'],
 'post_incident_analysis': {'root_causes': ['ADB exploitation',
                                            'Modular malware deployment',
                                            'Lack of device security']},
 'references': [{'source': 'Palo Alto Networks’ Unit 42'}],
 'response': {'third_party_assistance': 'Palo Alto Networks’ Unit 42'},
 'title': 'Kimwolf v7 Botnet Enhances DDoS Capabilities with Stealth and '
          'Resilience',
 'type': 'Botnet, DDoS',
 'vulnerability_exploited': ['ADB enabled on port 5555',
                             'Residential proxy services infiltration']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.