As cited
Citation snapshot as of .
threat intel
Kimwolf botnet rebuilt to survive takedowns, researchers say
Developers of the Kimwolf botnet have deployed a new version since February that evades detection and takedown efforts through two main improvements: HTTP/2 flood traffic disguised with Chrome browser fingerprints to bypass DDoS defenses, and command infrastructure migrated to the Ethereum Name Service and Tor to resist law enforcement seizure. Prior versions were disrupted in a March law enforcement operation that seized infrastructure and led to the arrest and extradition of an alleged Canadian operator.
Why it matters: Organizations defending against DDoS attacks need to update traffic analysis rules to detect HTTP/2 floods mimicking legitimate browsers, and security teams tracking botnet infrastructure should monitor blockchain-based and Tor-hidden command channels as threat actors adopt decentralized techniques to evade takedowns.
- Source published
- First seen by Cybersecurity Tracker