Kimwolf v7 Botnet Exploits HTTP/2 to Evade DDoS Detection
A new Android/IoT botnet variant uses HTTP/2 traffic to mimic legitimate browsing. Security teams need updated detection strategies to counter this stealthy DDoS threat.
TL;DR
- Kimwolf v7 is a new Android/IoT botnet discovered by Palo Alto Networks Unit 42 in February 2026.
- It leverages HTTP/2 protocol to disguise DDoS attack traffic as normal web browsing.
- The botnet targets both mobile devices and IoT endpoints to build resilient attack networks.
- Organizations should update network monitoring tools to detect abnormal HTTP/2 patterns.
- Traditional DDoS mitigation may fail against this new obfuscation technique.
Cybersecurity researchers have uncovered a sophisticated new variant of the Kimwolf botnet that's specifically designed to evade traditional DDoS detection mechanisms. This latest version, dubbed Kimwolf v7, represents a significant evolution in botnet-as-a-service operations, particularly in how it masks malicious traffic.
Unlike previous versions that relied on older HTTP protocols, Kimwolf v7 takes advantage of HTTP/2's performance benefits to blend attack traffic with legitimate user activity. This makes it considerably more challenging for standard network monitoring tools to distinguish between genuine web traffic and coordinated DDoS attacks.
Technical Evolution and Attack Methods
- Kimwolf v7 implements HTTP/2 protocol support to make malicious traffic appear identical to legitimate browser connections
- The botnet can dynamically adjust its attack parameters to mimic different types of web browsing behaviors
- It maintains persistence across both Android mobile devices and various IoT endpoints to maximize network size
- Command and control communications are encrypted and fragmented to avoid signature-based detection
Defensive Recommendations for Security Teams
- Update network monitoring solutions to analyze HTTP/2 traffic patterns for anomalies rather than just volume thresholds
- Implement behavioral analysis tools that can detect subtle differences between legitimate and bot-generated browsing patterns
- Review and enhance IoT device security policies to prevent unauthorized botnet recruitment
- Consider deploying protocol-specific DDoS protection that understands HTTP/2 characteristics and abuse patterns
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.