← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 13, 2026 · 06:16via CyberPress

Chrome Fingerprint Spoofing Makes Kimwolf HTTP/2 Floods Harder to Separate From Real Users

Brief

A newly identified version of the Kimwolf botnet is making distributed denial-of-service attacks harder to detect by making malicious traffic look like ordinary Chrome browser activity.

Known as Kimwolf v7, the Android and IoT malware adds an HTTP/2 flood capability that builds browser-like request fingerprints, making it more difficult for defenders to separate attack traffic from real users.

Kimwolf mainly targets Android TV boxes and set-top boxes. It is linked to the wider AISURU botnet operation, which initially focused on Linux IoT devices in 2024 before shifting toward Android-based targets in 2025.

Researchers identified the v7 variant on February 3, 2026, following public reporting from several security organizations.

The latest build focuses less on spreading and more on staying online and launching more effective DDoS attacks .

Read more on CyberPress