Cybersecurity Research

New Kimwolf v7 Botnet Targets Android IoT Devices with Advanced Evasion Tricks

Unit 42 · 11 Aug 2026
Key Takeaway Regularly update firmware and change default credentials on all internet-connected devices, including IoT equipment, to reduce the risk of botnet infection.

Researchers at Unit 42 have detailed a new version of the Kimwolf botnet, version 7, which has evolved to target Android Internet of Things (IoT) devices. This updated malware is designed to launch distributed denial-of-service (DDoS) attacks using HTTP/2 fingerprinting techniques, making it harder for defenders to detect and block malicious traffic patterns.

What makes Kimwolf v7 particularly concerning is its use of advanced infrastructure for resilience. The botnet uses Ethereum's ENS (Ethereum Name Service) to resolve command-and-control (C2) server addresses, a technique that makes it more difficult for security teams and law enforcement to disrupt the botnet by taking down traditional domains. Additionally, the malware includes a Tor-based backup routing system, giving it a fallback communication channel if its primary infrastructure is disrupted.

For small and medium businesses, this development is a reminder that IoT and connected devices—often overlooked in security planning—remain attractive targets for botnet operators. Compromised devices can be used to launch attacks against other organisations or degrade network performance without the owner even realising their equipment has been hijacked.

botnet IoT security DDoS Android malware

Summarised by CISO AI from Unit 42. We link back to every original so you can read it yourself.