Researchers identified Kimwolf v7, an updated variant of the Kimwolf/AISURU Android and Linux IoT botnet, adding an HTTP/2 flood capability designed to make distributed denial-of-service traffic resemble normal web browsing. The malware reportedly generates realistic Chrome-like browser fingerprints, complicating detection, while continuing to target Android TV devices through exposed ADB on port 5555 and Linux IoT systems through the AISURU branch. Analysts said the botnet has been active since at least mid-2024 and has continued evolving its Android infection chain with APKs disguised as system services that check for root access and execute an embedded ELF payload.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Unit 42 at Palo Alto Networks discovered Kimwolf v7 in February 2026. The new version added HTTP/2 DDoS capability, browser fingerprint imitation, and hardened command-and-control mechanisms using ENS and Tor.
Unit 42 observed the operators revert the malware library naming change in December 2025 after the November switch to libdevice.so. Both names also appear in the indicator-only reference.
Unit 42 observed the operators change a malware component name from libn[redacted]kernel.so to libdevice.so in November 2025. This was described as an operational security naming change.
Unit 42 identified eight Android APK samples between October and December 2025 that masqueraded as a system service and checked for root before executing an embedded ELF payload. The earliest identified sample targeted x86 architecture using the Dirty COW exploit.
Kimwolf has targeted Android TV devices since at least August 2025 by abusing exposed Android Debug Bridge on port 5555. Unit 42 assessed this reflected a shift toward an Android propagation model.
The Kimwolf/AISURU botnet was active by at least mid-2024, according to Unit 42. The malware family targeted Android and Linux IoT environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcemkd-cirt.mk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.