New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic
Security researchers at Palo Alto Networks' Unit 42 have identified a new, more advanced version of the Kimwolf (also known as AISURU) botnet, which infects Android devices and Internet of Things (IoT) gadgets. Dubbed Kimwolf v7, this variant was discovered in February 2026 and includes upgrades designed to make the botnet harder to detect and disrupt.
The most notable improvement is the addition of an HTTP/2-based communication method, which allows the botnet's distributed denial-of-service (DDoS) traffic to blend in with legitimate web browsing activity. This disguise makes it more difficult for standard security tools to distinguish malicious network traffic from normal internet use, increasing the botnet's chances of evading detection while overwhelming targeted systems with attack traffic.
Botnets like Kimwolf typically spread by compromising poorly secured smart devices and Android phones, then using their combined computing power to flood target websites or servers with traffic, knocking them offline. As these botnets grow more sophisticated, businesses relying on internet-connected devices—whether smart cameras, routers, or company-issued phones—face a greater risk of having their equipment silently recruited into these malicious networks.