Kimwolf v7 Botnet Evolution

Kimwolf v7 Botnet Evolution

Kimwolf v7 exploits Android IoT devices via HTTP/2 DDoS fingerprinting and Tor routing, with ties to Ethereum ENS C2 resolution.

Bottom line: Kimwolf v7's HTTP/2 DDoS fingerprinting technique enables it to evade traditional DDoS detection tools.

What's happening: Researchers have observed Kimwolf v7 targeting Android IoT devices, primarily in the United States and Brazil, since April 2022, using HTTP/2 DDoS fingerprinting to evade detection. The botnet uses Tor for backup routing and Ethereum ENS C2 resolution for command and control. The attack has been linked to the DarkSide ransomware group, which has been responsible for high-profile attacks in the United States, Canada, and Australia.

What to do: CISOs should prioritize implementing HTTP/2 DDoS detection and mitigation measures, and consider integrating Tor traffic monitoring to detect potential Kimwolf v7 activity.

Source: Unit 42