CVE Tools

Kimwolf v7: An Evolution of the Kimwolf Botnet

Palo Alto Unit 42By Asher Davila, Chris Navarrete, Doel Santos

Reported exploitedAndroid TV BoxesKimwolf

Our summary

Palo Alto Networks' Unit 42 has identified Kimwolf v7, a new iteration of the botnet that actively compromises Android TV and set-top boxes to launch sophisticated distributed denial-of-service attacks. This updated strain significantly enhances its offensive capabilities by introducing an HTTP/2 flood mechanism that spoofs legitimate browser fingerprints to evade detection. To ensure operational continuity against infrastructure takedowns, the malware utilizes a resilient command-and-control framework combining Ethereum Name Service resolution with a hard-coded Tor hidden service backup.

Read at Palo Alto Unit 42

Palo Alto Unit 42 publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store