threat_intelligence606 wordsRead on Arc Codex

Kimwolf botnet rebuilt to survive takedowns, researchers say

Kimwolf botnet rebuilt to survive takedowns, researchers say The developers of a notorious botnet that’s powered mostly by hijacked Android TV boxes and other internet-connected devices have released a new version built to blend attack traffic in with ordinary web browsing and to keep its command channels from being seized by law enforcement, researchers at Palo Alto Networks said in a report published Tuesday. The company’s Unit 42 threat intelligence group, which tracks the botnet as Kimwolf or Aisuru, said the newest version has been active since February, a month before authorities seized infrastructure powering previous versions of the botnet. The biggest change, according to the report, is a new flood method built on HTTP/2, the protocol that carries most web traffic today. A flood is the crude heart of a DDoS attack: thousands of infected devices send a target far more requests than it can answer. Rather than fire raw packets, this latest Kimwolf version operates with full browser fingerprints, copying the header order and behavior of the Chrome web browser. That matters because the usual defense against a flood is for tools to spot the fake traffic and drop or block it before it reaches the server. Traffic that looks like Chrome does not get dropped, so a site under attack must either serve every request and fall over, or start turning away the customers it cannot tell apart from the bots. The second change, according to researchers, looks like it was done to withstand further takedowns. Every bot has to ask a command server for orders, which is also what authorities aim to disrupt in botnet takedowns. Normally, the command server address sits inside the malware as a web domain name, so investigators who take that name from its registrar are able to disrupt an entire botnet. This Kimwolf version moves its command beyond registrar controls. The malware now looks up its command address in the Ethereum Name Service, a directory that lives on the Ethereum blockchain. A web address using this service can display the way a normal domain does, but the domain’s record sits in a ledger copied across thousands of computers worldwide. The malware carries five public Ethereum services and shuffles the order before each attempt, making it harder for defensive tools to block. Additionally, there is no company to serve with a law enforcement order and no domain record to seize. Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code. Tor resolves that address through its own network rather than the ordinary domain system, and it hides where the server actually sits, which leaves investigators without a host to contact. Researchers’ infrastructure analysis pointed to the machines powering the command structure to be located in Russia. Four of these servers shared a SSH host key, with further analysis finding that the servers sit in one network registered in Saint Petersburg. It’s unclear if this version was made by people behind previous iterations of the botnet, or a new person or threat group looking to capitalize on the botnet’s notoriety among malicious actors. Unit 42 did not respond to CyberScoop’s request for comment. Kimwolf, which splintered off from the record-setting Aisuru DDoS botnet last year, gained the widespread attention of security researchers when it temporarily claimed the top spot in Cloudflare’s global domain rankings in late October 2025. Previous versions of the botnet were disrupted by an international law enforcement operation in March that ended with Kimwolf’s infrastructure being seized. A Canadian man alleged to run the botnet was arrested in May and extradited to the United States.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.