Unit 42 identified Kimwolf v7, an evolution of the Kimwolf Android/IoT botnet that upgrades DDoS capabilities and C2 infrastructure resilience. The variant adds an HTTP/2 flood with complete Chrome browser fingerprint construction, a three-tier C2 system using Ethereum Name Service resolution, Tor .onion fallback, and a local proxy, and a NEON SIMD-optimized UDP flood tailored for ARM processors. The botnet primarily targets Android TV boxes via unauthenticated ADB instances and has consolidated to 15 DDoS methods while removing scanning and exploitation modules.
Kimwolf
3 posts
Kimwolf v7: An Evolution of the Kimwolf Botnet Latin America and the Caribbean Cybercrime Landscape In 2025, the Latin America and the Caribbean (LAC) region faced escalating cybercriminal activity driven by rapid digital adoption and economic instability. Threat actors heavily utilized Telegram and dark web forums to distribute ransomware, banking trojans, and infostealers, increasingly targeting the healthcare, manufacturing, and government sectors while adapting to law enforcement disruptions.
Akamai Helps Authorities Disrupt the World’s Largest IoT Botnets The US Department of Justice, alongside international authorities and industry partners including Akamai, successfully disrupted the Aisuru and Kimwolf IoT botnets. These hyper-volumetric botnets compromised up to 4 million IoT devices to launch record-breaking DDoS attacks exceeding 30 Tbps, which were used to cripple internet infrastructure and extort victims.