Palo Alto Networks Unit 42 has documented Kimwolf v7, the latest iteration of the AISURU Android and IoT botnet, which adds HTTP/2-based command and control protocols enabling DDoS attacks that blend with legitimate web browsing traffic — making detection by traditional network monitoring systems essentially impossible for organizations using standard volumetric or rate-limiting DDoS mitigation.
How HTTP/2-Based C2 Bypasses Traditional Detection
Kimwolf v7 sends requests through normal browser-compatible HTTP/2 frames that pass through standard DDoS mitigation filters as legitimate connections, instead of relying on the raw TCP floods or DNS amplification used by prior versions — attack methods easily detectable by volume-based systems. An HTTP/2 client making GET requests at normal browsing intervals is indistinguishable from a real user to any monitoring infrastructure that relies on packet rates, connection volumes, or traffic pattern analysis for threat detection.
Palo Alto Unit 42 identifies the first public reporting August 11, though network traffic captures suggest Palo Alto first identified Kimwolf v7 activity as early as February 2026 — meaning the botnet had been operating undetected using HTTP/2-based command and control protocols for months before public disclosure. The HTTP/2 approach represents a fundamental shift in DDoS tradecraft: instead of volumetric flooding, the botnet attacks by appearing entirely legitimate at the protocol level.
Expanding Device Pool Through IoT and Android Targeting
The AISURU botnet continues operating using HTTP/2-based C2 while gradually expanding its device pool through ongoing IoT and Android exploitation campaigns — establishing a growing infrastructure of compromised devices that can be weaponized for application-layer DDoS attacks indistinguishable from legitimate web traffic. Organizations managing large IoT deployments should monitor their device fleets for unauthorized communication with known Kimwolf command and control domains or IP ranges identified by Palo Alto researchers during their analysis.
Implications for Defenders Facing Protocol-Layer Evasion
The emergence of protocol-level evasion techniques within DDoS attacks means volumetric detection systems alone are no longer sufficient for comprehensive threat monitoring. Security teams should deploy behavioral analysis tools that can identify anomalous request patterns even when attack traffic masquerades as normal browsing, focusing on URL path uniformity, header consistency, and connection timing patterns rather than volume thresholds — the first meaningful operational guidance available for organizations defending against botnets operating at legitimate protocol sophistication levels.
