news.mlab.sh
Back to the feed
threat-intel

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

High
Image: The Hacker News
Summary

A new version of the Kimwolf/AISURU Android and IoT botnet, Kimwolf v7, has been discovered by Palo Alto Networks Unit 42. This version significantly improves its operational resilience and DDoS attack capabilities by utilizing HTTP/2-based floods, a tiered C2 infrastructure with Ethereum Name Service (ENS) and a Tor hidden service, and a local proxy architecture. The botnet primarily targets Android TV boxes and Linux IoT devices, leveraging ADB and exploiting vulnerabilities like Dirty COW to spread and conduct attacks. Organizations should treat Android TV boxes as untrusted and consider disabling ADB access.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.