hacker-news · Crawled Aug 11, 2026

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

3 IoCs 1 Malware
Read original article ↗

AI Summary

Palo Alto Networks Unit 42 discovered a new version of the Kimwolf/AISURU Android and IoT botnet, dubbed Kimwolf v7, in February 2026. This version enhances operational resilience by using HTTP/2-based DDoS floods that mimic legitimate browsing through complete browser fingerprints, making detection more difficult. It employs a tiered C2 infrastructure leveraging Ethereum Name Service (ENS), a hard-coded Tor .onion address, and a local proxy for traffic routing, while offloading initial access to external loaders and focusing on DDoS and proxy relay functions.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 3 extracted

Type Value Detail
Domain edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd[.]onion Details →
Filename libnkernel.so Details →
Filename libdevice.so Details →

MITRE ATT&CK TTPs 46 techniques

T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.004 Unix Shell · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1090.001 Internal Proxy · Command And Control T1090.002 External Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1090.004 Domain Fronting · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110.001 Password Guessing · Credential Access T1120 Peripheral Device Discovery · Discovery T1133 External Remote Services · Persistence T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1497 Virtualization/Sandbox Evasion · Defense Evasion T1498 Network Denial of Service · Impact T1498.001 Direct Network Flood · Impact T1543.001 Launch Agent · Persistence T1546.004 Unix Shell Configuration Modification · Privilege Escalation T1546.008 Accessibility Features · Privilege Escalation T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1572 Protocol Tunneling · Command And Control T1573 Encrypted Channel · Command And Control T1573.001 Symmetric Cryptography · Command And Control T1573.002 Asymmetric Cryptography · Command And Control T1573.003 T1573.003 T1573.004 T1573.004 T1583 Acquire Infrastructure · Resource Development T1588 Obtain Capabilities · Resource Development T1588.002 Tool · Resource Development