LIVE · cybersecurity feed
Live wire
malware

Kimwolf botnet rebuilt to survive takedowns, researchers say

Months after police seized its servers and arrested an alleged operator, the Kimwolf botnet is running code that disguises attacks as Chrome traffic and fetches its orders from the Ethereum blockchain. The post Kimwolf botnet rebuilt to survive takedowns, researchers say appeared first on CyberScoop.

zeroday.news ·

The Kimwolf botnet, known for its distributed denial-of-service (DDoS) attacks, has reportedly been rebuilt with new features designed to evade detection and resist law enforcement takedowns. Researchers at Palo Alto Networks' Unit 42, who track the botnet as Kimwolf or Aisuru, detailed these changes in a report published this week. The updated version of the botnet has been active since February, predating an international law enforcement operation in March that seized infrastructure associated with previous iterations.

One significant change is a new HTTP/2 flood method. Unlike earlier versions that might send raw packets, the new Kimwolf variant mimics legitimate Chrome web browser traffic, complete with full browser fingerprints and header order. This makes it challenging for defensive systems to distinguish malicious traffic from genuine user requests, forcing targeted websites to either process all requests and risk collapse or block what appears to be legitimate customer traffic.

To enhance its resilience against takedowns, the botnet has altered its command-and-control (C2) communication strategy. Previously, C2 server addresses were embedded as standard domain names within the malware, making them vulnerable to seizure by registrars. The new version now retrieves its C2 addresses from the Ethereum Name Service (ENS), a decentralized naming system built on the Ethereum blockchain. This mechanism stores domain records across a distributed ledger, making them difficult for a single entity to seize or disrupt. The malware is programmed with five public ENS addresses, which it shuffles before each connection attempt, further complicating blocking efforts.

As a fallback, if all five ENS addresses fail, the botnet is configured to connect to a fixed Tor hidden service address. Tor's network architecture obscures the physical location of the server, providing an additional layer of anonymity and making it harder for investigators to identify and target the host. Unit 42's infrastructure analysis suggests that the servers powering the botnet's command structure are located in Russia, with four sharing an SSH host key and residing within a single network registered in Saint Petersburg.

The Kimwolf botnet primarily compromises Android TV boxes and other internet-connected devices. It gained notoriety in late October 2025 when it briefly topped Cloudflare's global domain rankings. The March law enforcement operation led to the seizure of Kimwolf's infrastructure, and a Canadian man alleged to be an operator was arrested in May and subsequently extradited to the United States. It remains unclear whether the developers behind this new version are the same individuals responsible for previous iterations or a new group capitalizing on the botnet's reputation.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-58231high

Crooks Buy Expired Domains for Malware Delivery, Other Threats Detailed

Cybercriminals are exploiting expired domain names to distribute malware, a tactic highlighted in a recent security newsletter. The newsletter also covers a range of other threats including zero-day exploits in macOS and GeoServer, a data leak affecting Chess.com users, and attacks targeting Adobe Commerce and SharePoint.

breach

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That ch

malware

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they […]

ai

Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do

Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power'

breach

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit […]

patch

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat Research Unit report tracks a previously undocumented backdoor called PATCHCORD, […]