logo

Kimwolf botnet rebuilt to survive takedowns, researchers say

ID: 71ca42df-1aff-5742-a7e5-d803960b4399

STIX ID: report--71ca42df-1aff-5742-a7e5-d803960b4399

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

Author: Greg Otto

...
...

Palo Alto Networks' Unit 42 reports a new Kimwolf/Aisuru botnet variant that performs stealthy HTTP/2-based DDoS floods impersonating Chrome, and uses the Ethereum Name Service (ENS) plus a Tor fallback for resilient command-and-control; infrastructure analysis points to servers in Russia and the botnet has a recent history of large-scale attacks and partial takedowns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.