Kimwolf v7 Android Botnet Uses HTTP/2 DDoS and Ethereum ENS for Resilience
Palo Alto Networks Unit 42 discovered Kimwolf v7, a new version of the Kimwolf/AISURU Android and IoT botnet. This variant features significant improvements for operational resilience, including HTTP/2-based DDoS attacks that mimic legitimate browsing traffic. It also incorporates Ethereum ENS for C2 resolution and Tor for backup routing, making it harder to disrupt and detect.