VMTech
Discuss a project

Kimwolf v7 strengthens Android botnet DDoS and C2 resilience

Kimwolf v7 strengthens Android botnet DDoS and C2 resilience

Palo Alto Networks Unit 42 has identified Kimwolf v7, a new version of the Kimwolf/AISURU Android and Internet of Things botnet, which adds an HTTP/2 distributed denial-of-service flood designed to resemble legitimate browser activity. Discovered in February 2026, the variant constructs complete browser fingerprints at protocol and header level, making attack traffic more difficult to separate from normal browsing.

The malware also changes its command-and-control design to make disruption harder. It can query Ethereum Name Service records through legitimate public Ethereum RPC services to resolve command-and-control addresses, while retaining a hard-coded Tor hidden-service address as a backup. A local proxy at 127.0.0.1:23075 routes all command-and-control traffic, whether the destination is on the clearnet or Tor.

Focused DDoS payload, separate propagation

Kimwolf v7 removes scanning, exploitation and brute-force capabilities from the core binary. Unit 42 said this points to a split between the propagation pipeline and the payload: an external loader handles initial access, while Kimwolf concentrates on DDoS activity and proxy relay.

The botnet’s attack functions have been consolidated into 15 numbered methods, down from 43 text-named methods in earlier versions. Its HTTP/2 flood uses the nghttp2 library and reproduces browser-like behavior. It also includes a high-performance UDP flood function aimed at ARM processors, the architecture commonly used in Android TV boxes.

Android TV boxes remain the central exposure

Kimwolf has targeted Android TV boxes since August 2025, while the Linux-focused AISURU counterpart targets Linux IoT devices. The operation has been active since at least mid-2024. It commonly abuses residential proxy services to reach Android TVs with Android Debug Bridge enabled on port 5555 on local networks, then installs malware able to conduct DDoS attacks and relay malicious traffic.

After launching, the malware may masquerade as an Android system process such as netd_service. Unit 42 also observed Android APKs posing as a system service named SystemService. These packages probe for root access and execute a bundled ELF kernel payload; eight APK artifacts were identified between October and December 2025.

The earliest observed dropped sample targeted x86 and contained a Dirty COW exploit, which Unit 42 said suggests an evolution from traditional Linux exploitation to the current ADB-based Android propagation model. Changes between the filenames libn[redacted]kernel.so and libdevice.so during late 2025 further indicate operational-security adjustments.

Practical implications for enterprises

Kimwolf’s shift follows a broader pattern in which exposed consumer and IoT equipment can be enrolled for attacks; vulnerable infrastructure and attack chains highlights related risks from vulnerable infrastructure and attack chains, while this case centres on Android TV hardware and ADB exposure.

Organizations should treat Android TV boxes as untrusted devices and segment them from enterprise networks. Disabling ADB, or limiting it to USB-only access, removes the primary propagation path identified by Unit 42 and reduces the chance that a TV box becomes a DDoS node or traffic relay.

#cybersecurity#ddos#androidsecurity#iotsecurity
Open analytics
On the site 0 views
min read 4 12.08.2026
Instagram

Kimwolf v7 strengthens Android botnet DDoS and C2 resilience

Open the post on Instagram ↗