← Blog · · df00tech

Kimwolf v7 Android Botnet Update Blends DDoS Traffic Into Normal HTTP/2 Browsing

security-news campaign

What happened

Researchers at Palo Alto Networks Unit 42 reported discovering a new version of the Kimwolf (also tracked as AISURU) Android and IoT botnet in February 2026. According to Unit 42, Kimwolf v7 introduces operational resilience improvements and an HTTP/2-based capability designed to make its distributed denial-of-service (DDoS) traffic blend in with legitimate browsing activity. Full technical details of the update were still emerging at the time of reporting.

Why it matters

Kimwolf/AISURU is an established Android and IoT botnet family used to conduct DDoS attacks. A version that disguises attack traffic as normal HTTP/2 browsing traffic makes network-layer detection and filtering harder for defenders who rely on traditional volumetric or protocol-anomaly signatures. Any organization running internet-facing services — and any environment with unmanaged or poorly patched Android/IoT devices that could be recruited into the botnet — is potentially affected, either as a source of compromised nodes or as a target of resulting DDoS traffic.

What defenders should watch for

  • Monitor for anomalous HTTP/2 connection patterns and request behavior from IoT/Android device segments, even when traffic superficially resembles normal browsing.
  • Review network segmentation and egress controls for consumer/IoT devices on corporate or hosting networks, since these are typical Kimwolf/AISURU recruitment targets.
  • Ensure DDoS mitigation and rate-limiting controls account for application-layer (HTTP/2) floods, not just volumetric attacks, since evasion at this layer can slip past coarse-grained defenses.
  • Track threat intelligence updates from Unit 42 and other researchers for indicators of compromise, C2 infrastructure, and detection signatures as they are published.

Developing story

This is net-new intelligence based on a single research disclosure, and details are likely to evolve as more analysis is published. No detection rule accompanies this note. For the original reporting, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.