Kimwolf v7: Evolution of AISURU Botnet
Score: 8/10

Kimwolf v7: Evolution of AISURU Botnet

AISURU threat actors deployed Kimwolf v7 targeting Android TV boxes and IoT devices using Ethereum Name Service (ENS) for resilient C2 and advanced HTTP/2 DDoS fingerprinting.

Executive Summary

Palo Alto Networks Unit 42 has identified version 7 of the Kimwolf (also known as AISURU) botnet, which has evolved from targeting Linux IoT devices to primarily impacting Android TV and set-top boxes. This version demonstrates a significant increase in infrastructure resilience and attack sophistication, utilizing a three-tier C2 resolution system involving Ethereum Name Service (ENS) and Tor hidden services to bypass traditional domain takedowns.

Technically, Kimwolf v7 utilizes the Android Debug Bridge (ADB) over port 5555 as its primary propagation vector. The malware features 15 distinct DDoS attack methods, most notably an HTTP/2 flood that spoofs complete browser fingerprints (Chrome/Safari) to evade application-layer detection. It also leverages ARM NEON SIMD instructions to maximize UDP flood performance on mobile processors.

This evolution marks a transition toward a modular operational model where propagation and attack capabilities are separated. The use of blockchain-based naming systems and Tor redundancy indicates a professionalized adversary committed to maintaining long-term botnet availability despite active industry takedown efforts.

Key Details

Threat Name

Kimwolf v7

Affects

Linux kernel, x86 Linux systems

Adversary

AISURU

Malware/Tools

Kimwolf, AISURU

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth9

Sources