New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic
Palo Alto Networks says the upgraded Android and smart-device botnet hides its floods inside HTTP/2 sessions that look like ordinary browsing.

Key points
- Palo Alto Networks Unit 42 uncovered Kimwolf v7 in February 2026, a new version of the Kimwolf/AISURU botnet that hijacks Android phones and internet-connected devices.
- The malware adds an HTTP/2-based flood method that mimics normal web browsing, making attack traffic harder for defenders to spot.
- Kimwolf is built for DDoS attacks (distributed denial-of-service, where thousands of infected devices bombard a website until it falls over).
- The botnet targets Android devices and IoT hardware, which owners rarely patch.
- Researchers say the upgrade is aimed at operational resilience: keeping the botnet alive longer and its traffic harder to filter.
Researchers at Palo Alto Networks Unit 42 have found a fresh version of a botnet that quietly turns phones and smart devices into weapons for online attacks.
They call it Kimwolf v7, the latest build of the Kimwolf family, also tracked as AISURU, spotted in February 2026. We first covered this botnet family on 28 May 2026.
A botnet is a network of hacked devices a criminal controls remotely. Owners usually have no idea their gadget is part of one.
Kimwolf infects Android phones and Internet of Things (IoT) hardware: security cameras, home routers, smart plugs, cheap streaming boxes. Most of these devices ship with weak passwords and never get software updates, which makes them easy targets.
What does the new version actually do?
Kimwolf v7 is built to knock websites offline while looking innocent. Its job is launching DDoS attacks, where a swarm of infected devices hits the same site at once until it buckles.
The new trick is an HTTP/2-based flood. HTTP/2 is the protocol your browser uses to load pages from your bank or a retail site. By dressing attack traffic as normal HTTP/2 requests, Kimwolf blends in with real visitors, and defensive tools hunting for obviously junk traffic struggle to pick it out. It's a logical evolution: as we reported on 11 August 2026, terabit-scale DDoS attacks jumped fivefold in a single quarter, and volume alone no longer distinguishes an attack from a busy afternoon.
Unit 42 also flagged changes aimed at what they call operational resilience, meaning the botnet is harder to knock down and its command channels are tougher to cut. That mirrors the playbook we saw in the Dysphoria botnet's blockchain rebuild reported 27 July 2026.
Who is at risk?
The direct victims are websites and services under the flood: gaming platforms, online shops, government portals. When a site's under a Kimwolf attack, customers see an outage or a crawling load time.
The indirect victims are device owners. Your old Android tablet or a cheap camera could be sending attack traffic right now, on your home connection, with no visible sign.
| Detail | What Unit 42 reports |
|---|---|
| Botnet name | Kimwolf v7 (also tracked as AISURU) |
| Discovered by | Palo Alto Networks Unit 42 |
| Date found | February 2026 |
| Target devices | Android phones, IoT hardware |
| Main capability | DDoS attacks using HTTP/2 floods |
Should you worry?
Yes, selectively. Keep devices updated. If your phone or router stopped getting security patches, it's time to replace it. Change default admin passwords on every smart device you own. Unusual slowness or an unexplained spike in data usage is worth investigating.
For defenders, the operational lesson is sharper: DDoS filters tuned only for high-volume junk traffic will miss v7. HTTP/2 behaviour needs inspection, not just packet counts.
Unit 42 hasn't published a full list of affected device models. Until it does, the working assumption should be the usual one: any cheap, unpatched, internet-connected device is a candidate. The botnet's longevity is the part worth watching, not just its new flood method.



