Kimwolf v7: An Evolution of the Kimwolf Botnet
ID: b832abf5-c2bb-5ae0-b377-2ced1ea7a37b
STIX ID: report--b832abf5-c2bb-5ae0-b377-2ced1ea7a37b
Feed Name: Palo Alto Networks Unit 42
Date Published: 2026-08-11
Date Updated: 2026-08-11
Author: Asher Davila, Chris Navarrete and Doel Santos
This report analyzes Kimwolf v7, an evolved Android/IoT botnet that targets Android TV/set-top boxes and delivers advanced DDoS capabilities (including an HTTP/2 flood that spoofs browser fingerprints and an ARM NEON-optimized UDP flood). The variant implements a three-tier C2 resolution system (ENS via hard-coded Ethereum RPC endpoints with an operator RPC facade, a Tor .onion fallback, and a local proxy), removes scanning/exploitation functionality in favor of a focused attack/proxy payload, and includes multiple IoCs (file hashes, APKs, domains, IPs, and a Tor hidden service) and operational recommendations for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
