< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

Kimwolf botnet upgraded to use Chrome fingerprints and Ethereum

Researchers at Palo Alto Networks’ Unit 42 have identified a sophisticated new version of the Kimwolf botnet, designated Kimwolf v7. The malware primarily targets Android TV boxes and set-top boxes to facilitate large-scale distributed denial-of-service (DDoS) attacks.

To evade detection, the latest version utilizes an HTTP/2-based flood that mimics the behavior and header order of the Chrome web browser. By constructing complete browser fingerprints, the botnet makes its attack traffic nearly indistinguishable from legitimate web browsing, complicating efforts for defenders to implement rate-limiting or fingerprint-based mitigation.

To increase resilience against law enforcement takedowns, the botnet has integrated blockchain technology. It uses the Ethereum Name Service (ENS) to resolve command-and-control (C2) addresses. The malware queries five hard-coded, public Ethereum-based RPC endpoints to find its instructions, making it difficult to disrupt the infrastructure by blocking individual domains. Additionally, the botnet includes a Tor .onion hidden service as a backup for flexible routing.

Entities

Chrome · Ethereum · Kimwolf · Palo Alto Networks · Unit 42