Security1 publisher3 min readPublished Updated
Kimwolf's new flood wears Chrome's fingerprints and takes orders from a blockchain
Unit 42 says the Android TV box botnet now floods over HTTP/2 with full Chrome fingerprints and resolves its command server through the Ethereum Name Service, with Tor as a fallback.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Palo Alto Networks' Unit 42 published a report on Tuesday on a new version of the botnet it tracks as Kimwolf or Aisuru.
- The new version was built to blend attack traffic in with ordinary web browsing and to keep its command channels from being seized by law enforcement.
- The botnet is powered mostly by hijacked Android TV boxes and other internet-connected devices.
- Unit 42 said the newest version has been active since February, a month before authorities seized infrastructure powering previous versions of the botnet.
- Previous versions of the botnet were disrupted by an international law enforcement operation in March that ended with Kimwolf's infrastructure being seized.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Palo Alto Networks' Unit 42 said in a report published Tuesday that the botnet it tracks as Kimwolf, also known as Aisuru, has a new version whose attack traffic is built to blend in with ordinary web browsing and whose command channel is designed to survive law enforcement seizure [1] [2]. For anyone operating DDoS mitigation, that shifts the job from identifying bad traffic to deciding how many real customers you are willing to turn away.
The botnet runs mostly on hijacked Android TV boxes and other internet-connected devices [3]. Unit 42 says this version has been active since February, one month before an international law enforcement operation seized the infrastructure behind previous versions in March [4] [5]. That ordering matters: the rebuild was already in the field when the takedown landed, so it is better read as anticipation than as reaction [6]. A Canadian man alleged to run the botnet was arrested in May and extradited to the United States [7].
The change with the most immediate operational consequence is a flood method built on HTTP/2, the protocol that carries most web traffic today [8]. Instead of firing raw packets, the malware operates with full browser fingerprints, copying the header order and behavior of Chrome [9]. The standard defense against a flood is to spot the fake traffic and drop it before it reaches the server [10]. According to the report, traffic that looks like Chrome does not get dropped, which leaves a site under attack with two options: serve every request and fall over, or start refusing the customers it cannot tell apart from the bots [11]. Signature matching has nothing to match on, and anomaly scoring cannot separate a Chrome-shaped bot from Chrome.
The second change targets the takedown playbook. Normally the command server address sits inside the malware as a domain name, so investigators who pull that name from its registrar can disrupt the whole botnet [12]. This version looks up its command address in the Ethereum Name Service, a directory whose records live in a ledger copied across thousands of computers, so there is no company to serve with a legal order and no domain record to seize [13]. The malware carries five public Ethereum services and shuffles their order before each attempt, which makes blocking harder [14]. If all five fail, it falls back to a fixed Tor hidden service address written into the code, resolved through Tor's own network, which also conceals where the server sits [15]. That is six resolution paths to sever rather than one registrar to call [16].
Unit 42's infrastructure analysis placed the machines behind the command structure in Russia, with four of the servers sharing an SSH host key and sitting in one network registered in Saint Petersburg [17] [18]. The report says it is unclear whether this version was built by the people behind earlier iterations or by someone new trading on the botnet's notoriety [19]. Unit 42 did not respond to CyberScoop's request for comment [20]. Kimwolf splintered off from the record-setting Aisuru DDoS botnet last year and drew broad researcher attention when it briefly claimed the top spot in Cloudflare's global domain rankings in late October 2025 [21] [22].
Watch whether mitigation vendors respond by pushing customers toward challenge-based defenses, because the cost of that move is friction for legitimate users rather than a clean block. Watch also whether the Saint Petersburg hosting gives responders anything actionable, since the ENS and Tor layers remove the registrar leverage that ended the previous version in March [5] [13] [15].