type: incident ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [incident, botnet, android, ddos, malware, http2, mobile] ยท confidence: high ยท affected_sectors: [technology, finance, government] ยท au_impact: false
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Palo Alto Networks Unit 42's analysis of the evolving Kimwolf Android botnet's v7 shows it using HTTP/2-based DDoS that mimics legitimate browser traffic to evade detection and filtering.
Summary
The Kimwolf Android botnet โ in its v7 iteration โ uses HTTP/2-based DDoS that mimics legitimate browser traffic to evade detection and filtering, advancing the family's stealth and amplification capability. The research is the primary analysis of a live threat and predates general press coverage. The research was published by Unit 42 (2026-08-11).
Date
- Published: 2026-08-11
Source
- Unit 42 โ 2026-08-11