Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [incident, botnet, android, ddos, malware, http2, mobile] ยท confidence: high ยท affected_sectors: [technology, finance, government] ยท au_impact: false

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Palo Alto Networks Unit 42's analysis of the evolving Kimwolf Android botnet's v7 shows it using HTTP/2-based DDoS that mimics legitimate browser traffic to evade detection and filtering.

Summary

The Kimwolf Android botnet โ€” in its v7 iteration โ€” uses HTTP/2-based DDoS that mimics legitimate browser traffic to evade detection and filtering, advancing the family's stealth and amplification capability. The research is the primary analysis of a live threat and predates general press coverage. The research was published by Unit 42 (2026-08-11).

Date

  • Published: 2026-08-11

Source