Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Cybersecurity researchers have identified Kimwolf v7, a new version of the Android and IoT botnet that enhances DDoS attacks by using HTTP/2 traffic to mimic legitimate browsing, improving its stealth and resilience.

Cybersecurity researchers discovered Kimwolf v7, a new version of the Android and IoT botnet Kimwolf/AISURU, in February 2026. Palo Alto Networks Unit 42 reported that the botnet uses HTTP/2 to make DDoS traffic appear as legitimate browsing, improving operational resilience and attack effectiveness.