CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Kimwolf botnet rebuilt to survive takedowns, researchers say

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4269

As cited

Citation snapshot as of .

threat intel

Kimwolf botnet rebuilt to survive takedowns, researchers say

Developers of the Kimwolf botnet have deployed a new version since February that evades detection and takedown efforts through two main improvements: HTTP/2 flood traffic disguised with Chrome browser fingerprints to bypass DDoS defenses, and command infrastructure migrated to the Ethereum Name Service and Tor to resist law enforcement seizure. Prior versions were disrupted in a March law enforcement operation that seized infrastructure and led to the arrest and extradition of an alleged Canadian operator.

Why it matters: Organizations defending against DDoS attacks need to update traffic analysis rules to detect HTTP/2 floods mimicking legitimate browsers, and security teams tracking botnet infrastructure should monitor blockchain-based and Tor-hidden command channels as threat actors adopt decentralized techniques to evade takedowns.

Source published
First seen by Cybersecurity Tracker

Source attribution