Unit 42 identified Kimwolf v7, an evolution of the Kimwolf Android/IoT botnet that upgrades DDoS capabilities and C2 infrastructure resilience. The variant adds an HTTP/2 flood with complete Chrome browser fingerprint construction, a three-tier C2 system using Ethereum Name Service resolution, Tor .onion fallback, and a local proxy, and a NEON SIMD-optimized UDP flood tailored for ARM processors. The botnet primarily targets Android TV boxes via unauthenticated ADB instances and has consolidated to 15 DDoS methods while removing scanning and exploitation modules.
Android botnet
1 post
Kimwolf v7: An Evolution of the Kimwolf Botnet