New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic
Palo Alto Networks says the upgraded Android and smart-device botnet hides its floods inside HTTP/2 sessions that look like ordinary browsing.

Key points
- Palo Alto Networks Unit 42 uncovered Kimwolf v7 in February 2026, a new version of the Kimwolf/AISURU botnet that hijacks Android phones and internet-connected devices.
- The malware adds an HTTP/2-based flood method that mimics normal web browsing, making the attack traffic harder for defenders to spot.
- Kimwolf is built for DDoS attacks (distributed denial-of-service, where thousands of infected devices bombard a website until it falls over).
- The botnet targets Android devices and IoT gear (internet-connected cameras, routers, and smart home kit), which owners rarely patch.
- Researchers say the upgrade is aimed at operational resilience: keeping the botnet alive longer and its traffic harder to filter.
Researchers at Palo Alto Networks Unit 42 have found a fresh version of a botnet that quietly turns phones and smart devices into weapons for online attacks.
They call it Kimwolf v7. It is the latest build of the Kimwolf family, also tracked as AISURU, and it was spotted in February 2026.
A botnet, in plain terms, is a network of hacked devices that a criminal controls from a distance. Owners usually have no idea their gadget is part of it.
Kimwolf infects Android phones and Internet of Things (IoT) hardware. IoT means everyday objects that connect to the internet: security cameras, home routers, smart plugs, baby monitors, cheap streaming boxes. Many of these devices ship with weak passwords and never get software updates, which makes them easy pickings.
What does the new version actually do?
Kimwolf v7 is built to knock websites offline while looking innocent. Its main job is launching DDoS attacks, where a swarm of infected devices all hit the same website at once until it collapses under the load.
The new trick in v7 is an HTTP/2-based flood. HTTP/2 is the modern protocol your browser uses to load pages from sites like your bank or your GP surgery. By dressing its attack traffic up as normal HTTP/2 requests, Kimwolf blends in with real visitors. Defensive tools that look for obviously junk traffic have a harder time picking it out.
Unit 42 also flagged changes aimed at what they call operational resilience, meaning the botnet is harder to knock down and its command channels are tougher to cut.
Who is at risk?
The direct victims are the websites and services hit by the DDoS floods. Those can be anything from gaming platforms to online shops to government portals. When a site is under a Kimwolf attack, ordinary customers see it as an outage or a very slow load.
The indirect victims are the people who own the infected devices. Your old Android tablet or a cheap camera bought years ago could be sending attack traffic right now, using your home internet, without any visible sign.
| Detail | What Unit 42 reports |
|---|---|
| Botnet name | Kimwolf v7 (also tracked as AISURU) |
| Discovered by | Palo Alto Networks Unit 42 |
| Date found | February 2026 |
| Target devices | Android phones, IoT hardware |
| Main capability | DDoS attacks using HTTP/2 floods |
What should ordinary people do?
Keep your devices updated. If your phone or router stopped getting security patches, it is time to replace it. Change default admin passwords on any smart device you own. If your home internet feels unusually slow or your data usage spikes for no reason, that is worth looking into.
For businesses, the takeaway from the reporting, including coverage by The Hacker News, is that DDoS defences tuned only for obvious junk traffic will miss v7. Filters need to inspect HTTP/2 behaviour, not just volume.
Unit 42 has not published a full list of affected device models. Until it does, the safest assumption is the usual one: any cheap, unpatched, internet-connected device in your house is a candidate.



