CYBERSECURITYTRACKER
TRACKING7,735 stories in this site build1,671 vulnerability news stories in this site build
Permanent story citation

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4248

As cited

Copy frozen at (site build).

threat intel

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Palo Alto Networks Unit 42 discovered Kimwolf v7, a new variant of the Kimwolf/AISURU Android and IoT botnet, in February 2026. The updated version includes HTTP/2-based capabilities designed to enhance operational resilience and conduct distributed denial-of-service attacks while disguising malicious traffic as legitimate browsing activity.

Why it matters: Android and IoT device owners face infection from an improved botnet that evades detection through legitimate-looking HTTP/2 traffic; practitioners managing mobile and IoT environments should monitor for Kimwolf v7 indicators and review DDoS mitigation strategies.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Researchers at Palo Alto Networks Unit 42 identified a new variant of the Kimwolf/AISURU botnet, labeled Kimwolf v7, in February 2026. The variant introduces enhancements aimed at increasing the botnet's resilience and its ability to launch distributed denial-of-service attacks. Notably, it incorporates an HTTP/2 mechanism designed to mimic legitimate web traffic.

Why it matters: Defenders of HTTP/2-accessible applications must monitor for traffic that mimics legitimate browsing but exhibits abnormal request rates, as Kimwolf v7 can use this technique to evade detection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Researchers at Palo Alto Networks Unit 42 identified a new variant of the Kimwolf/AISURU botnet, labeled Kimwolf v7, in February 2026. The variant introduces enhancements aimed at increasing the botnet's resilience and its ability to launch distributed denial-of-service attacks. Notably, it incorporates an HTTP/2 mechanism designed to mimic legitimate web traffic.

Why it matters: Defenders of HTTP/2-accessible applications must monitor for traffic that mimics legitimate browsing but exhibits abnormal request rates, as Kimwolf v7 can use this technique to evade detection.

VendorsGooglePalo Alto Networks
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary