Kimwolf Botnet Version 7 Enhances DDoS Attack Methods Using HTTP/2

Kimwolf Botnet Version 7 Enhances DDoS Attack Methods Using HTTP/2

First seen 12 Aug 2026, 08:06 UTC ThehackernewsCyberscoopunit42.paloaltonetworks.com 83% similarity 72.0

Article Content

Browse articles
ThreatCluster

The Kimwolf botnet, primarily composed of hijacked Android TV boxes, has released a new version that utilizes HTTP/2 to disguise DDoS attack traffic as legitimate web browsing. This update, active since February 2026, aims to evade detection by mimicking browser behavior, making it difficult for defenses to differentiate between real and malicious traffic. Additionally, the botnet has shifted its command and control infrastructure to the Ethereum Name Service, complicating takedown efforts by law enforcement. The command structure appears to be hosted on servers located in Russia, with multiple public Ethereum addresses used to enhance resilience against disruptions. The botnet's fallback mechanism includes a Tor hidden service address, further obscuring its operational footprint. Researchers have not confirmed whether the new version was developed by the original creators or a new group. The botnet's evolution poses a significant threat to online services and infrastructure.

Key Points: • Kimwolf botnet now uses HTTP/2 to disguise DDoS traffic as legitimate browsing. • Command and control has moved to the Ethereum Name Service, complicating takedown efforts. • The botnet's infrastructure is believed to be located in Russia, with fallback mechanisms using Tor.

ThreatCluster AI How this analysis works

Timeline

2026-02-01
New version of Kimwolf botnet becomes active
The latest iteration of the Kimwolf botnet was reported to be operational, utilizing advanced techniques for DDoS attacks.
Cyberscoop
2026-08-11
Research report on Kimwolf v7 published
Palo Alto Networks' Unit 42 released findings on the botnet's new capabilities and attack methods.
Thehackernews
2026-08-12
Cyberscoop article published
Cyberscoop reported on the latest developments regarding the Kimwolf botnet and its evasion techniques.
Cyberscoop

Community

Browse all →