🟠 High | Source: The Hacker News
A new version of the Kimwolf (also known as AISURU) Android and IoT botnet, tracked as v7, has been identified by Palo Alto Networks Unit 42 in February 2026. The updated botnet uses HTTP/2-based DDoS traffic engineered to mimic legitimate browser activity, making it significantly harder to detect and block. This development raises the bar for defenders attempting to filter malicious traffic at the network edge.
Security Architect’s Take: Review your DDoS mitigation controls — particularly any HTTP/2-aware WAF or Layer 7 filtering rules — to ensure they rely on behavioural analysis and anomaly detection rather than simple traffic pattern matching, as Kimwolf v7 is specifically designed to evade signature-based defences. Consider enabling advanced bot management features on your CDN or load balancer that use TLS fingerprinting and request-rate heuristics rather than static block lists.
Original advisory: Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing