Cyberscoop
Kimwolf Botnet Version 7 Enhances DDoS Attack Methods Using HTTP/2
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Kimwolf botnet, primarily composed of hijacked Android TV boxes, has released a new version that utilizes HTTP/2 to disguise DDoS attack traffic as legitimate web browsing. This update, active since February 2026, aims to evade detection by mimicking browser behavior, making it difficult for defenses to differentiate between real and malicious traffic. Additionally, the botnet has shifted its command and control infrastructure to the Ethereum Name Service, complicating takedown efforts by law enforcement. The command structure appears to be hosted on servers located in Russia, with multiple public Ethereum addresses used to enhance resilience against disruptions. The botnet's fallback mechanism includes a Tor hidden service address, further obscuring its operational footprint. Researchers have not confirmed whether the new version was developed by the original creators or a new group. The botnet's evolution poses a significant threat to online services and infrastructure.
Key Points: • Kimwolf botnet now uses HTTP/2 to disguise DDoS traffic as legitimate browsing. • Command and control has moved to the Ethereum Name Service, complicating takedown efforts. • The botnet's infrastructure is believed to be located in Russia, with fallback mechanisms using Tor.