As cited
Copy frozen at (site build).
threat intel
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Palo Alto Networks Unit 42 discovered Kimwolf v7, a new variant of the Kimwolf/AISURU Android and IoT botnet, in February 2026. The updated version includes HTTP/2-based capabilities designed to enhance operational resilience and conduct distributed denial-of-service attacks while disguising malicious traffic as legitimate browsing activity.
Why it matters: Android and IoT device owners face infection from an improved botnet that evades detection through legitimate-looking HTTP/2 traffic; practitioners managing mobile and IoT environments should monitor for Kimwolf v7 indicators and review DDoS mitigation strategies.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Researchers at Palo Alto Networks Unit 42 identified a new variant of the Kimwolf/AISURU botnet, labeled Kimwolf v7, in February 2026. The variant introduces enhancements aimed at increasing the botnet's resilience and its ability to launch distributed denial-of-service attacks. Notably, it incorporates an HTTP/2 mechanism designed to mimic legitimate web traffic.
Why it matters: Defenders of HTTP/2-accessible applications must monitor for traffic that mimics legitimate browsing but exhibits abnormal request rates, as Kimwolf v7 can use this technique to evade detection.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Researchers at Palo Alto Networks Unit 42 identified a new variant of the Kimwolf/AISURU botnet, labeled Kimwolf v7, in February 2026. The variant introduces enhancements aimed at increasing the botnet's resilience and its ability to launch distributed denial-of-service attacks. Notably, it incorporates an HTTP/2 mechanism designed to mimic legitimate web traffic.
Why it matters: Defenders of HTTP/2-accessible applications must monitor for traffic that mimics legitimate browsing but exhibits abnormal request rates, as Kimwolf v7 can use this technique to evade detection.
- Source published
- First seen by Cybersecurity Tracker