unit42 · Crawled Aug 11, 2026
Kimwolf v7: An Evolution of the Kimwolf Botnet
26 IoCs 1 Malware
Read original article ↗
AI Summary
Unit42 identified a new version (v7) of the Kimwolf Android/IoT botnet, which enhances DDoS capabilities and strengthens command-and-control (C2) resilience. The malware targets Android TV boxes and IoT devices via unsecured ADB ports, using HTTP/2-based DDoS floods that spoof browser fingerprints to mimic legitimate traffic. Its C2 infrastructure leverages Ethereum Name Service (ENS) resolution via public RPC endpoints, a suspected operator-controlled RPC facade, and a fallback to a hard-coded Tor .onion address, ensuring persistence against takedown attempts.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 26 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 406647de09a0ffa279756b4ccb344b1b76a333320c5b50fd367901fa006cf0ff | Details → |
| MD5 | d759364844d78a728505fb0485c3adbc | Details → |
| SHA-256 | 345222bca004595977f971d76900b0c65fd9bf9d91c50cd0c5bf5a93f1ad9e49 | Details → |
| MD5 | 036bcb62be72c4663b9564955f93b05f | Details → |
| SHA-256 | 2ec2e85b0358e0c681cb5067489a9086ec97dbbf7e3c952dd9cd496b319d5af5 | Details → |
| MD5 | 33faca1e0090f6b12eff703daf4606e4 | Details → |
| SHA-256 | 951c94809aa6c7ab587125f9d4df30fa6a49ee0cbba76a4b7ceedaaa0e5dcd36 | Details → |
| SHA-256 | f07821e313c16cbbd82def45094a22c8d474164051bdbc7648d6869e012014b4 | Details → |
| Filename | libn[redacted]kernel.so | Details → |
| Filename | libdevice.so | Details → |
| Filename | libcow.so | Details → |
| Domain | 0xrpc[.]io | Details → |
| Domain | eth[.]llamarpc[.]com | Details → |
| Domain | ethereum-rpc[.]publicnode[.]com | Details → |
| Domain | eth[.]merkle[.]io | Details → |
| Domain | eth[.]rpcuniverse[.]com | Details → |
| Domain | rpcuniverse[.]com | Details → |
| Domain | avax[.]rpcuniverse[.]com | Details → |
| IP | 23[.]94[.]221[.]104 | Details → |
| IP | 212[.]193[.]31[.]119 | Details → |
| IP | 212[.]193[.]31[.]122 | Details → |
| IP | 212[.]193[.]31[.]92 | Details → |
| IP | 212[.]193[.]31[.]158 | Details → |
| IP | 212[.]193[.]31[.]102 | Details → |
| Domain | edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd[.]onion | Details → |
| SHA-256 | f3e8a55a2a3ea7c7b6676e90f4f49a2c55b13065b68ee50c51cc35fe2b5c3237 | Details → |
MITRE ATT&CK TTPs 46 techniques
T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.004 Unix Shell · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1090.001 Internal Proxy · Command And Control T1090.002 External Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1090.004 Domain Fronting · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110.001 Password Guessing · Credential Access T1120 Peripheral Device Discovery · Discovery T1133 External Remote Services · Persistence T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1497 Virtualization/Sandbox Evasion · Defense Evasion T1498 Network Denial of Service · Impact T1498.001 Direct Network Flood · Impact T1543.001 Launch Agent · Persistence T1546.004 Unix Shell Configuration Modification · Privilege Escalation T1546.008 Accessibility Features · Privilege Escalation T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1572 Protocol Tunneling · Command And Control T1573 Encrypted Channel · Command And Control T1573.001 Symmetric Cryptography · Command And Control T1573.002 Asymmetric Cryptography · Command And Control T1573.003 T1573.003 T1573.004 T1573.004 T1583 Acquire Infrastructure · Resource Development T1588 Obtain Capabilities · Resource Development T1588.002 Tool · Resource Development