Security1 distinct publisher3 min readUpdated
Unit 42 says the Android TV box botnet now floods over HTTP/2 with full Chrome fingerprints and resolves its command server through the Ethereum Name Service, with Tor as a fallback.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Palo Alto Networks' Unit 42 said in a report published Tuesday that the botnet it tracks as Kimwolf, also known as Aisuru, has a new version whose attack traffic is built to blend in with ordinary web browsing and whose command channel is designed to survive law enforcement seizure [1] [2]. For anyone operating DDoS mitigation, that shifts the job from identifying bad traffic to deciding how many real customers you are willing to turn away.
The botnet runs mostly on hijacked Android TV boxes and other internet-connected devices [3]. Unit 42 says this version has been active since February, one month before an international law enforcement operation seized the infrastructure behind previous versions in March [4] [5]. That ordering matters: the rebuild was already in the field when the takedown landed, so it is better read as anticipation than as reaction [6]. A Canadian man alleged to run the botnet was arrested in May and extradited to the United States [7].
The change with the most immediate operational consequence is a flood method built on HTTP/2, the protocol that carries most web traffic today [8]. Instead of firing raw packets, the malware operates with full browser fingerprints, copying the header order and behavior of Chrome [9]. The standard defense against a flood is to spot the fake traffic and drop it before it reaches the server [10]. According to the report, traffic that looks like Chrome does not get dropped, which leaves a site under attack with two options: serve every request and fall over, or start refusing the customers it cannot tell apart from the bots [11]. Signature matching has nothing to match on, and anomaly scoring cannot separate a Chrome-shaped bot from Chrome.
The second change targets the takedown playbook. Normally the command server address sits inside the malware as a domain name, so investigators who pull that name from its registrar can disrupt the whole botnet [12]. This version looks up its command address in the Ethereum Name Service, a directory whose records live in a ledger copied across thousands of computers, so there is no company to serve with a legal order and no domain record to seize [13]. The malware carries five public Ethereum services and shuffles their order before each attempt, which makes blocking harder [14]. If all five fail, it falls back to a fixed Tor hidden service address written into the code, resolved through Tor's own network, which also conceals where the server sits [15]. That is six resolution paths to sever rather than one registrar to call [16].
Unit 42's infrastructure analysis placed the machines behind the command structure in Russia, with four of the servers sharing an SSH host key and sitting in one network registered in Saint Petersburg [17] [18]. The report says it is unclear whether this version was built by the people behind earlier iterations or by someone new trading on the botnet's notoriety [19]. Unit 42 did not respond to CyberScoop's request for comment [20]. Kimwolf splintered off from the record-setting Aisuru DDoS botnet last year and drew broad researcher attention when it briefly claimed the top spot in Cloudflare's global domain rankings in late October 2025 [21] [22].
Watch whether mitigation vendors respond by pushing customers toward challenge-based defenses, because the cost of that move is friction for legitimate users rather than a clean block. Watch also whether the Saint Petersburg hosting gives responders anything actionable, since the ENS and Tor layers remove the registrar leverage that ended the previous version in March [5] [13] [15].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Palo Alto Networks' Unit 42 published a report on Tuesday on a new version of the botnet it tracks as Kimwolf or Aisuru.
The new version was built to blend attack traffic in with ordinary web browsing and to keep its command channels from being seized by law enforcement.
The botnet is powered mostly by hijacked Android TV boxes and other internet-connected devices.
Unit 42 said the newest version has been active since February, a month before authorities seized infrastructure powering previous versions of the botnet.
Previous versions of the botnet were disrupted by an international law enforcement operation in March that ended with Kimwolf's infrastructure being seized.
A Canadian man alleged to run the botnet was arrested in May and extradited to the United States.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor report, one outlet, specific artifacts
The technical detail is unusually concrete for a single-source story — a named protocol change, five Ethereum resolvers with shuffled ordering, a hardcoded Tor fallback, four servers sharing an SSH host key in a Saint Petersburg-registered network — which is hard to produce without real samples. But everything traces to one Unit 42 report relayed by one publisher, the report itself is not quoted at length or linked in the supplied text, no independent researcher or mitigation provider corroborates it, and Unit 42 did not respond to a comment request. Attribution of the variant's authorship is explicitly left open by the researchers.
Live in the wild, scale undisclosed
This is real operational malware rather than a proposal: the variant is reported active since February, the prior lineage was significant enough to trigger an international seizure in March and an arrest and extradition in May, and the family briefly topped Cloudflare's global domain rankings in October 2025. What is absent is any measure of the new variant's reach — no infection counts, no attack volumes, no named victims, and no confirmation that its HTTP/2 Chrome-fingerprint flood has actually defeated production mitigation at scale.
Capability described, impact unproven
The 'rebuilt to survive takedowns' framing is anchored in specific engineering choices, so it is not empty hype. It does run modestly ahead of the evidence in two ways: the claim that Chrome-lookalike traffic leaves defenders only bad options is presented as consequence rather than demonstrated outcome, and the claim of seizure-proof command infrastructure is asserted from design rather than tested against an actual attempted disruption of the Ethereum Name Service path or the Saint Petersburg hosts. No attack data accompanies the capability description.
Vendor threat research as sole basis
The entire story originates with a commercial security vendor's threat intelligence group, and Palo Alto Networks sells the detection and DDoS-relevant capabilities that the reported gap implies customers need. That is a standard and often productive incentive, but here it is unmitigated: no independent corroboration, no counter-view from mitigation providers, and no vendor response to the reporter's questions. The publisher does not surface this incentive.
Plausible and specific, but uncorroborated
Confidence is limited by structure rather than by internal inconsistency: one publisher, one vendor source, no second reading of the samples, and month-level dating for several timeline events. The corroborating context that does exist — a March seizure, a May arrest, the October 2025 Cloudflare ranking — supports the family's significance but not the specific technical claims about the new variant, and the researchers leave authorship open.
build
Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout1 distinct publisher
security
Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures1 distinct publisher
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 11, 2026