Palo Alto Networks: Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2

Palo Alto Networks: Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2

Kimwolf v7 Botnet Leverages HTTP/2 to Evade DDoS Detection

Palo Alto Networks’ Unit 42 has uncovered Kimwolf v7, the latest version of the AISURU Android and IoT botnet, which introduces HTTP/2-based command and control (C2) protocols to launch stealthy DDoS attacks. Unlike traditional botnets that rely on detectable volumetric floods or DNS amplification, Kimwolf v7 mimics legitimate web browsing traffic by sending requests via HTTP/2 frames rendering it nearly invisible to standard network monitoring and rate-limiting defenses.

First publicly reported on August 11, evidence suggests the botnet had been active as early as February 2026, operating undetected for months. The shift to HTTP/2 represents a tactical evolution, replacing brute-force flooding with protocol-level deception. By blending in with normal traffic, the botnet bypasses volumetric detection systems that rely on packet rates or connection thresholds.

The AISURU botnet continues to expand its device pool through ongoing exploitation of IoT and Android devices, creating a growing infrastructure capable of application-layer DDoS attacks indistinguishable from genuine user activity. Organizations with large IoT deployments are advised to monitor for unauthorized communications with known Kimwolf C2 domains or IP ranges identified by Palo Alto researchers.

For defenders, the emergence of protocol-level evasion underscores the limitations of volumetric detection alone. Security teams must adopt behavioral analysis tools to detect anomalies in request patterns, such as URL path uniformity, header consistency, and connection timing even when attack traffic appears legitimate. This marks a new challenge in botnet defense, as attackers increasingly exploit protocol sophistication to evade traditional safeguards.

Source: https://dailysecurityreview.com/threat-actors/kimwolf-v7-android-botnet-evades-ddos-mitigation-using-http-2-c2/

Palo Alto Networks TPRM report: https://www.rankiteo.com/company/unit42

"id": "uni1786559239",
"linkid": "unit42",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'type': 'Organization'}],
 'attack_vector': 'HTTP/2-based C2 protocols',
 'date_detected': '2026-02',
 'date_publicly_disclosed': '2026-08-11',
 'description': 'Palo Alto Networks’ Unit 42 has uncovered *Kimwolf v7*, the '
                'latest version of the AISURU Android and IoT botnet, which '
                'introduces HTTP/2-based command and control (C2) protocols to '
                'launch stealthy DDoS attacks. Unlike traditional botnets that '
                'rely on detectable volumetric floods or DNS amplification, '
                'Kimwolf v7 mimics legitimate web browsing traffic by sending '
                'requests via HTTP/2 frames, rendering it nearly invisible to '
                'standard network monitoring and rate-limiting defenses. The '
                'botnet exploits IoT and Android devices to create a growing '
                'infrastructure capable of application-layer DDoS attacks '
                'indistinguishable from genuine user activity.',
 'impact': {'operational_impact': 'Application-layer DDoS attacks evading '
                                  'detection',
            'systems_affected': 'IoT and Android devices'},
 'lessons_learned': 'The emergence of protocol-level evasion underscores the '
                    'limitations of volumetric detection alone. Security teams '
                    'must adopt behavioral analysis tools to detect anomalies '
                    'in request patterns, such as URL path uniformity, header '
                    'consistency, and connection timing, even when attack '
                    'traffic appears legitimate.',
 'post_incident_analysis': {'corrective_actions': 'Adopt behavioral analysis '
                                                  'tools; monitor for '
                                                  'unauthorized C2 '
                                                  'communications',
                            'root_causes': 'Exploitation of IoT and Android '
                                           'devices; use of HTTP/2 to evade '
                                           'detection'},
 'recommendations': 'Organizations with large IoT deployments are advised to '
                    'monitor for unauthorized communications with known '
                    'Kimwolf C2 domains or IP ranges. Defenders should adopt '
                    'behavioral analysis tools to detect anomalies in HTTP/2 '
                    'traffic patterns.',
 'references': [{'source': 'Palo Alto Networks’ Unit 42'}],
 'response': {'adaptive_behavioral_waf': 'Recommended',
              'enhanced_monitoring': 'Recommended (behavioral analysis tools)'},
 'threat_actor': 'AISURU botnet (Kimwolf v7)',
 'title': 'Kimwolf v7 Botnet Leverages HTTP/2 to Evade DDoS Detection',
 'type': 'DDoS',
 'vulnerability_exploited': 'Exploitation of IoT and Android devices'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.