CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Kimwolf botnet rebuilt to survive takedowns, researchers say

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4269

As cited

Copy frozen at (site build).

threat intel

Kimwolf botnet rebuilt to survive takedowns, researchers say

Developers of the Kimwolf botnet have deployed a new version since February that evades detection and takedown efforts through two main improvements: HTTP/2 flood traffic disguised with Chrome browser fingerprints to bypass DDoS defenses, and command infrastructure migrated to the Ethereum Name Service and Tor to resist law enforcement seizure. Prior versions were disrupted in a March law enforcement operation that seized infrastructure and led to the arrest and extradition of an alleged Canadian operator.

Why it matters: Organizations defending against DDoS attacks need to update traffic analysis rules to detect HTTP/2 floods mimicking legitimate browsers, and security teams tracking botnet infrastructure should monitor blockchain-based and Tor-hidden command channels as threat actors adopt decentralized techniques to evade takedowns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Kimwolf botnet rebuilt to survive takedowns, researchers say

Palo Alto Networks researchers documented a rebuilt version of the Kimwolf botnet active since February that uses HTTP/2-based distributed denial of service (DDoS) floods mimicking Chrome browser traffic to evade detection filters. The new variant shifts command and control infrastructure to the Ethereum Name Service blockchain and Tor hidden services to resist law enforcement seizures, with fallback mechanisms and shuffled lookup orders to maintain resilience. Infrastructure analysis suggests the servers operate from Saint Petersburg, though it remains unclear whether original or new operators designed this iteration.

Why it matters: Organizations defending against DDoS attacks face a harder detection problem if botnets disguise malicious traffic as legitimate Chrome requests, and infrastructure defenders must monitor blockchain-based and Tor-routed command channels that bypass traditional domain registrar takedowns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Kimwolf botnet rebuilt to survive takedowns, researchers say

Palo Alto Networks researchers documented a rebuilt version of the Kimwolf botnet active since February that uses HTTP/2-based distributed denial of service (DDoS) floods mimicking Chrome browser traffic to evade detection filters. The new variant shifts command and control infrastructure to the Ethereum Name Service blockchain and Tor hidden services to resist law enforcement seizures, with fallback mechanisms and shuffled lookup orders to maintain resilience. Infrastructure analysis suggests the servers operate from Saint Petersburg, though it remains unclear whether original or new operators designed this iteration.

Why it matters: Organizations defending against DDoS attacks face a harder detection problem if botnets disguise malicious traffic as legitimate Chrome requests, and infrastructure defenders must monitor blockchain-based and Tor-routed command channels that bypass traditional domain registrar takedowns.

VendorsGooglePalo Alto NetworksCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary