Threats

Kimwolf Botnet Evolves

August 12, 2026 04:01 · 10 min read
Kimwolf Botnet Evolves

Introduction to Kimwolf Botnet

The Kimwolf botnet, also known as Aisuru, has been a notorious threat in the cybersecurity world. Recently, researchers at Palo Alto Networks' Unit 42 threat intelligence group discovered a new version of the botnet that has been active since February. This new version has been designed to blend attack traffic with ordinary web browsing and protect its command channels from seizure by law enforcement.

Changes in the New Version

The biggest change in the new version is the use of a new flood method built on HTTP/2, which is the protocol that carries most web traffic today. This flood method operates with full browser fingerprints, copying the header order and behavior of the Chrome web browser. This makes it difficult for defensive tools to spot and block the fake traffic, as it looks like legitimate Chrome traffic.

Another significant change is the way the botnet's command server address is handled. Previously, the command server address was stored as a web domain name, which made it easy for investigators to disrupt the botnet by seizing the domain. However, in the new version, the command server address is stored in the Ethereum Name Service, a directory that lives on the Ethereum blockchain. This makes it much harder for defensive tools to block the command server, as there is no company to serve with a law enforcement order and no domain record to seize.

Infrastructure Analysis

Researchers' infrastructure analysis pointed to the machines powering the command structure being located in Russia. Four of these servers shared a SSH host key, with further analysis finding that the servers sit in one network registered in Saint Petersburg. It's unclear if this version was made by the people behind previous iterations of the botnet or a new person or threat group looking to capitalize on the botnet's notoriety among malicious actors.

Background of Kimwolf Botnet

Kimwolf botnet splintered off from the record-setting Aisuru DDoS botnet last year and gained widespread attention of security researchers when it temporarily claimed the top spot in Cloudflare's global domain rankings in late October 2025. Previous versions of the botnet were disrupted by an international law enforcement operation in March, which ended with Kimwolf's infrastructure being seized. A Canadian man alleged to run the botnet was arrested in May and extradited to the United States.

Conclusion

The new version of the Kimwolf botnet is a significant evolution of the threat, with changes designed to make it more difficult to detect and disrupt. The use of HTTP/2 and the Ethereum Name Service makes it harder for defensive tools to block the botnet's command server, and the location of the command structure in Russia adds an extra layer of complexity. As the cybersecurity world continues to evolve, it's essential to stay vigilant and adapt to new threats like the Kimwolf botnet.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free