Security researchers from Palo Alto Networks’ Unit 42 have spotted a new version of the Kimwolf botnet that focuses on stealth and resilience. Kimwolf, active since 2024 and linked to the Aisuru ecosystem, has already infected well over a million Android and IoT devices, especially cheap Android TV and set‑top boxes.
The latest release, Kimwolf v7, introduces an HTTP/2 DDoS feature that tries to mimic real Chrome browser traffic. By generating detailed browser fingerprints, its attack traffic can blend in with normal visitors, making it harder for defenses to filter out. The botnet now supports 15 different DDoS methods, including TCP, UDP, DNS, ICMP, TLS/HTTPS, and HTTP/2 floods, with one UDP mode tuned for ARM chips often found in TV boxes. Interestingly, scanning and exploitation functions appear removed, suggesting Kimwolf now relies on other tools to handle initial infections.
The operators have also hardened their command‑and‑control setup. Kimwolf can pull server details from Ethereum Name Service (ENS) records using public Ethereum RPC providers, and it has a Tor fallback if that fails. Users are urged to treat low‑cost Android TV boxes with caution, disable or restrict ADB, and watch for unusual Ethereum, Tor traffic, or suspicious processes such as “netd_service”.
- Cyber Dispatch
The latest release, Kimwolf v7, introduces an HTTP/2 DDoS feature that tries to mimic real Chrome browser traffic. By generating detailed browser fingerprints, its attack traffic can blend in with normal visitors, making it harder for defenses to filter out. The botnet now supports 15 different DDoS methods, including TCP, UDP, DNS, ICMP, TLS/HTTPS, and HTTP/2 floods, with one UDP mode tuned for ARM chips often found in TV boxes. Interestingly, scanning and exploitation functions appear removed, suggesting Kimwolf now relies on other tools to handle initial infections.
The operators have also hardened their command‑and‑control setup. Kimwolf can pull server details from Ethereum Name Service (ENS) records using public Ethereum RPC providers, and it has a Tor fallback if that fails. Users are urged to treat low‑cost Android TV boxes with caution, disable or restrict ADB, and watch for unusual Ethereum, Tor traffic, or suspicious processes such as “netd_service”.
- Cyber Dispatch
Thailand plans mandatory multi-factor authentication after massive data leak.
Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach.
Telegram turns 13 today, on August 14, 2026. It launched on August 14, 2013.
🎉1
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks.
"Apple devices now give you alerts if you're cool and badass."
"Apple devices now give you alerts if you're cool and badass."
Scottish prosecutors cast eye over leaky supplier after staff data exposed.
New Zealand says China tried using space investments to spy on local affairs.
France's top court has blocked a law banning social media access for children under 15.
Elon Musk makes all Government censorship requests publicly visible in its open-source X algorithm.