Particle.news

Kimwolf v7 Masks DDoS Traffic as Chrome Browsing and Hides Its Command Servers

Unit 42 warns the changes make registrar takedowns ineffective, increasing the chance that attack traffic will pass for ordinary web requests.

Overview

  • Palo Alto Networks Unit 42 says it found the evolved Kimwolf v7 in February 2026 and that the new build sends HTTP/2 floods that copy Chrome header order and behavior so malicious requests look like real browser traffic.
  • The malware resolves its command address through the Ethereum Name Service, which stores records on the Ethereum blockchain so there is no single registrar to seize, and it includes a hard-coded Tor .onion fallback to hide host locations.
  • Researchers observed the operators stripped scanner and exploit code from the core binary, which indicates initial access and device compromise are now handled by separate external loaders.
  • Kimwolf now mainly recruits Android TV boxes by abusing residential proxy services to reach devices with ADB exposed on port 5555, so researchers advise treating Android TVs as untrusted, segmenting them, and disabling or restricting ADB.
  • Infrastructure traces point to servers in a Saint Petersburg network that shared SSH keys but do not prove actor identity, and defenders should expect DDoS defenses and incident response to change as attackers blend attacks with normal web traffic.