Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Nigel Farage looks trapped and rattled – now the nationalist tide can be turned | Rafael Behr

    August 12, 2026

    Another OpenAI executive takes off

    August 12, 2026

    Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Nigel Farage looks trapped and rattled – now the nationalist tide can be turned | Rafael Behr
    • Another OpenAI executive takes off
    • Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
    • CPI Inflation Day: Where the money’s flowing in bitcoin and ether markets
    • What you need to know about the solar eclipse in eastern England
    • In India, sacred groves serve as vital nurseries for future forests
    • Despite the drought, don’t give up on our native plants | Plants
    • Total Eclipse – The New York Times
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 11, 2026Botnet / Vulnerability

    Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks.

    The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026.

    “Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints,” researchers Asher Davila, Chris Navarrete, and Doel Santos said. “This makes attack traffic more difficult to distinguish from legitimate browsing.”

    The botnet also aims to make its command-and-control (C2) infrastructure more resistant to takedown efforts by using a tiered mechanism that employs Ethereum Name Service (ENS) to obtain the C2 address, a hard-coded Tor .onion hidden service, and a local proxy for routing between clearnet and Tor, while removing all scanning, exploitation, and brute-force functionality.

    The removal of the scanner and exploit modules is an indication that the threat actors behind the operation have split the propagation pipeline from the core payload, offloading the task to an external loader for initial access, while the Kimwolf binary handles DDoS attacks and proxy relay.

    Cybersecurity

    Kimwolf is known to target Android TV boxes since August 2025, while its Linux counterpart, AISURU, primarily focuses on Linux IoT devices. The botnet has been active since at least mid-2024.

    The botnet typically abuses residential proxy services to reach Android TVs that ship with Android Debug Bridge (ADB) enabled on port 5555 on local networks and install malware capable of conducting DDoS attacks and acting as a relay to ferry malicious traffic.

    Once launched, the malware attempts to mask itself as seemingly legitimate Android system processes (e.g., “netd_service”) to fly under the radar. Some of the newly observed features in the new version are as follows –

    • Carry out HTTP/2 flood attacks powered by the nghttp2 library along with constructing complete browser fingerprints that mirror legitimate browser behavior at the protocol and header level
    • Using legitimate public Ethereum RPC services to query ENS domain records and resolve C2 addresses
    • A backup C2 mechanism that uses a Tor .onion hidden service (“edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd[.]onion”) that’s hard-coded into the binary
    • A local proxy architecture that routes all C2 traffic through 127.0.0[.]1:23075, irrespective of whether it’s headed to clearnet or Tor
    • A high-performance UDP flood function that specifically targets ARM processors found in Android TV boxes
    • Consolidate all DDoS attack commands to 15 numbered methods, down from 43 text-named methods found in prior versions

    The Kimwolf operators have also been found to distribute Android APK packages that masquerade as a system service called SystemService, probe for root access, and execute a bundled ELF kernel payload inside. Eight such APK artifacts have been identified between October and December 2025.

    “The earliest dropped sample, targeting the x86 architecture with a Dirty COW exploit, suggests the family evolved from traditional Linux exploitation toward the current ADB-based Android propagation model,” Unit 42 said. “The transition from libn[redacted]kernel.so to the less conspicuous libdevice.so filename in November 2025, followed by a revert in December, indicates active operational security adjustments.”

    Cybersecurity

    The disclosure comes as a number of new botnet malware families have been detected in recent months –

    • AryStinger, which enlists older, vulnerable home routers into a network for distributed reconnaissance and proxying
    • RustDuck, which hijacks home routers, IP cameras, Android boxes, and poorly secured servers to rope them into a network for conducting DDoS attacks
    • NadMesh, which combines scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform that’s designed to scan for Redis, Docker, MCP, Kubernetes, ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances, drop an SSH backdoor, and harvest credentials, environment variables, account tokens, and AWS and Docker configurations
    • Tengu, a Mirai-derived IoT malware that employs Telnet brute-force to hijack IoT devices and run instructions that allow it to launch DoS attacks, gather network configuration information, set up persistence, exfiltrate system metadata, execute commands, download additional payloads, and turn the infected node into a proxy.

    “Kimwolf v7 is a focused evolution of an already large-scale botnet,” Unit 42 said. “Organizations should treat Android TV boxes as untrusted and segment them from enterprise networks. Disabling ADB or restricting it to USB-only access removes the primary propagation vector for this botnet.”

    Android Botnet Browsing DDoS HTTP2 Kimwolf Legitimate Traffic
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

    Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

    Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

    Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

    Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

    DeadLock ransomware uses blockchain to resist infrastructure takedown

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Nigel Farage looks trapped and rattled – now the nationalist tide can be turned | Rafael Behr

    August 12, 2026

    Another OpenAI executive takes off

    August 12, 2026

    Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

    August 12, 2026

    CPI Inflation Day: Where the money’s flowing in bitcoin and ether markets

    August 12, 2026
    Latest Posts

    I grew up near Andy Burnham. This is what shaped our new PM | Andy Burnham

    July 25, 2026

    The Economic Philosophy of Britain’s Andy Burnham

    July 25, 2026

    Samsung Wallet Will Add Stablecoin Support, Including USDC

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Nigel Farage looks trapped and rattled – now the nationalist tide can be turned | Rafael Behr

    August 12, 2026

    Another OpenAI executive takes off

    August 12, 2026

    Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.