CVE Tools
Back to feed
Exploited in the wild Android TV Boxes Kimwolf ddos-botnet Palo Alto Networks malware

Kimwolf v7: An Evolution of the Kimwolf Botnet

Palo Alto Unit 42·By Asher Davila, Chris Navarrete, Doel Santos··14 min read
CVE Tools coverage

Palo Alto Networks' Unit 42 has identified Kimwolf v7, a new iteration of the botnet that actively compromises Android TV and set-top boxes to launch sophisticated distributed denial-of-service attacks. This updated strain significantly enhances its offensive capabilities by introducing an HTTP/2 flood mechanism that spoofs legitimate browser fingerprints to evade detection. To ensure operational continuity against infrastructure takedowns, the malware utilizes a resilient command-and-control framework combining Ethereum Name Service resolution with a hard-coded Tor hidden service backup.

Content Warning

We are providing a content warning because the following article contains usage of a racial slur by a threat actor, which Unit 42 does not condone in any instance. We have partially redacted the racial slur, but preserved some references to it in order to provide researchers with the ability to identify it and check IoCs as needed.

Continue reading on Palo Alto Unit 42