Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
A new version of the Kimwolf/AISURU Android and IoT botnet, Kimwolf v7, has been discovered by Palo Alto Networks Unit 42. This version significantly improves its operational resilience and DDoS attack capabilities by utilizing HTTP/2-based floods, a tiered C2 infrastructure with Ethereum Name Service (ENS) and a Tor hidden service, and a local proxy architecture. The botnet primarily targets Android TV boxes and Linux IoT devices, leveraging ADB and exploiting vulnerabilities like Dirty COW to spread and conduct attacks. Organizations should treat Android TV boxes as untrusted and consider disabling ADB access.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
