Kimwolf v7 Hides DDoS Traffic Behind Browsers

Unit 42 identified Kimwolf v7, a new Android TV and set-top box botnet variant that adds HTTP/2-based DDoS floods and tougher command-and-control in one package. The malware was found in threat hunting after takedown activity, and the operators have already been using it against consumer Android boxes since the botnet’s shift to that platform in 2025. The flood is built to look like ordinary browsing: instead of sending stripped bot requests, Kimwolf v7 assembles a full browser fingerprint over HTTP/2, which makes it harder for filters to separate attack traffic from real web users. For control, the binary carries Ethereum Name Service (ENS) lookups and a hard-coded Tor backup, so if a domain or endpoint is taken down, the bot can still find its way back to command servers through other paths. That puts the story on two defensive fronts at once: the traffic is harder to signature out, and the control channel is harder to break cleanly. For anyone watching proxy, DNS, or Tor-exposed infrastructure, the useful shift is that cheap consumer boxes can now be kept in play even after ordinary sinkholing or takedowns interrupt the first route to them.

Part of the PlainSec briefing for 2026-08-11

Editions

Sources