Bottom line: Kimwolf v7's HTTP/2 DDoS fingerprinting technique enables it to evade traditional DDoS detection tools.
What's happening: Researchers have observed Kimwolf v7 targeting Android IoT devices, primarily in the United States and Brazil, since April 2022, using HTTP/2 DDoS fingerprinting to evade detection. The botnet uses Tor for backup routing and Ethereum ENS C2 resolution for command and control. The attack has been linked to the DarkSide ransomware group, which has been responsible for high-profile attacks in the United States, Canada, and Australia.
What to do: CISOs should prioritize implementing HTTP/2 DDoS detection and mitigation measures, and consider integrating Tor traffic monitoring to detect potential Kimwolf v7 activity.