Executive Summary
Palo Alto Networks Unit 42 has identified version 7 of the Kimwolf (also known as AISURU) botnet, which has evolved from targeting Linux IoT devices to primarily impacting Android TV and set-top boxes. This version demonstrates a significant increase in infrastructure resilience and attack sophistication, utilizing a three-tier C2 resolution system involving Ethereum Name Service (ENS) and Tor hidden services to bypass traditional domain takedowns.
Technically, Kimwolf v7 utilizes the Android Debug Bridge (ADB) over port 5555 as its primary propagation vector. The malware features 15 distinct DDoS attack methods, most notably an HTTP/2 flood that spoofs complete browser fingerprints (Chrome/Safari) to evade application-layer detection. It also leverages ARM NEON SIMD instructions to maximize UDP flood performance on mobile processors.
This evolution marks a transition toward a modular operational model where propagation and attack capabilities are separated. The use of blockchain-based naming systems and Tor redundancy indicates a professionalized adversary committed to maintaining long-term botnet availability despite active industry takedown efforts.
