Palo Alto Networks Unit 42 identified Kimwolf v7, an upgraded Android and IoT botnet variant capable of conducting DDoS attacks that masquerade as legitimate HTTP/2 browser traffic. The discovery came in February 2026.
Kimwolf, also known as AISURU, targets both mobile devices and IoT infrastructure. Version 7 represents a tactical evolution designed to evade detection and increase attack effectiveness. The botnet's HTTP/2 implementation allows attackers to generate DDoS traffic that appears indistinguishable from normal web browsing activity. This obfuscation technique complicates mitigation efforts for defenders monitoring network traffic.
The botnet's operational improvements enhance its resilience against takedown attempts and security interventions. Researchers noted the variant demonstrates increased sophistication in command-and-control communications and payload delivery mechanisms.
Android and IoT devices remain high-value targets for botnet operators because they often run outdated firmware lacking current security patches. Compromised devices become nodes in distributed attack infrastructure, with owners typically unaware of participation. A single botnet can commandeer thousands or millions of devices to orchestrate large-scale DDoS campaigns against critical infrastructure, financial institutions, or commercial websites.
Organizations face two distinct risks. First, their IoT and mobile deployments may already harbor Kimwolf infections, contributing to attacks against third parties. Second, they remain potential targets of DDoS campaigns orchestrated by operators controlling similar botnets. The HTTP/2 evasion technique specifically complicates traditional rate-limiting defenses that rely on traffic pattern recognition.
Mitigation requires device hardening through firmware updates, network segmentation isolating IoT from core systems, and behavioral monitoring for anomalous outbound connections. Security teams should conduct asset inventories to identify unpatched Android and IoT endpoints. Palo
