CyberSecurity News
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
AI summary
Cybersecurity researchers have found a new version of the Kimwolf Android and IoT botnet with improvements for resilience and conducting DDoS attacks. The new version, Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. Kimwolf v7 utilizes HTTP/2 to make its DDoS traffic appear similar to legitimate browsing activity. This capability is a significant enhancement to the botnet's operations. The discovery highlights the evolving nature of the Kimwolf botnet. Kimwolf v7's use of HTTP/2 allows it to blend its malicious traffic with normal user activity.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

