As cited
Copy frozen at (site build).
threat intel
Kimwolf botnet rebuilt to survive takedowns, researchers say
Developers of the Kimwolf botnet have deployed a new version since February that evades detection and takedown efforts through two main improvements: HTTP/2 flood traffic disguised with Chrome browser fingerprints to bypass DDoS defenses, and command infrastructure migrated to the Ethereum Name Service and Tor to resist law enforcement seizure. Prior versions were disrupted in a March law enforcement operation that seized infrastructure and led to the arrest and extradition of an alleged Canadian operator.
Why it matters: Organizations defending against DDoS attacks need to update traffic analysis rules to detect HTTP/2 floods mimicking legitimate browsers, and security teams tracking botnet infrastructure should monitor blockchain-based and Tor-hidden command channels as threat actors adopt decentralized techniques to evade takedowns.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Kimwolf botnet rebuilt to survive takedowns, researchers say
Palo Alto Networks researchers documented a rebuilt version of the Kimwolf botnet active since February that uses HTTP/2-based distributed denial of service (DDoS) floods mimicking Chrome browser traffic to evade detection filters. The new variant shifts command and control infrastructure to the Ethereum Name Service blockchain and Tor hidden services to resist law enforcement seizures, with fallback mechanisms and shuffled lookup orders to maintain resilience. Infrastructure analysis suggests the servers operate from Saint Petersburg, though it remains unclear whether original or new operators designed this iteration.
Why it matters: Organizations defending against DDoS attacks face a harder detection problem if botnets disguise malicious traffic as legitimate Chrome requests, and infrastructure defenders must monitor blockchain-based and Tor-routed command channels that bypass traditional domain registrar takedowns.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Kimwolf botnet rebuilt to survive takedowns, researchers say
Palo Alto Networks researchers documented a rebuilt version of the Kimwolf botnet active since February that uses HTTP/2-based distributed denial of service (DDoS) floods mimicking Chrome browser traffic to evade detection filters. The new variant shifts command and control infrastructure to the Ethereum Name Service blockchain and Tor hidden services to resist law enforcement seizures, with fallback mechanisms and shuffled lookup orders to maintain resilience. Infrastructure analysis suggests the servers operate from Saint Petersburg, though it remains unclear whether original or new operators designed this iteration.
Why it matters: Organizations defending against DDoS attacks face a harder detection problem if botnets disguise malicious traffic as legitimate Chrome requests, and infrastructure defenders must monitor blockchain-based and Tor-routed command channels that bypass traditional domain registrar takedowns.
- Source published
- First seen by Cybersecurity Tracker