Kimwolf botnet rebuilt to survive takedowns, researchers say
ID: 71ca42df-1aff-5742-a7e5-d803960b4399
STIX ID: report--71ca42df-1aff-5742-a7e5-d803960b4399
Feed Name: CyberScoop
Threat Score
Palo Alto Networks' Unit 42 reports a new Kimwolf/Aisuru botnet variant that performs stealthy HTTP/2-based DDoS floods impersonating Chrome, and uses the Ethereum Name Service (ENS) plus a Tor fallback for resilient command-and-control; infrastructure analysis points to servers in Russia and the botnet has a recent history of large-scale attacks and partial takedowns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
