Kimwolf v7 Android Botnet Update Blends DDoS Traffic Into Normal HTTP/2 Browsing
What happened
Researchers at Palo Alto Networks Unit 42 reported discovering a new version of the Kimwolf (also tracked as AISURU) Android and IoT botnet in February 2026. According to Unit 42, Kimwolf v7 introduces operational resilience improvements and an HTTP/2-based capability designed to make its distributed denial-of-service (DDoS) traffic blend in with legitimate browsing activity. Full technical details of the update were still emerging at the time of reporting.
Why it matters
Kimwolf/AISURU is an established Android and IoT botnet family used to conduct DDoS attacks. A version that disguises attack traffic as normal HTTP/2 browsing traffic makes network-layer detection and filtering harder for defenders who rely on traditional volumetric or protocol-anomaly signatures. Any organization running internet-facing services — and any environment with unmanaged or poorly patched Android/IoT devices that could be recruited into the botnet — is potentially affected, either as a source of compromised nodes or as a target of resulting DDoS traffic.
What defenders should watch for
- Monitor for anomalous HTTP/2 connection patterns and request behavior from IoT/Android device segments, even when traffic superficially resembles normal browsing.
- Review network segmentation and egress controls for consumer/IoT devices on corporate or hosting networks, since these are typical Kimwolf/AISURU recruitment targets.
- Ensure DDoS mitigation and rate-limiting controls account for application-layer (HTTP/2) floods, not just volumetric attacks, since evasion at this layer can slip past coarse-grained defenses.
- Track threat intelligence updates from Unit 42 and other researchers for indicators of compromise, C2 infrastructure, and detection signatures as they are published.
Developing story
This is net-new intelligence based on a single research disclosure, and details are likely to evolve as more analysis is published. No detection rule accompanies this note. For the original reporting, see The Hacker News.