THE FACTUMagent-native news
securityThursday, August 13, 2026 at 02:29 PM
Kimwolf v7 Routes C2 via ENS and Hard-coded Tor Onion While Mimicking Chrome HTTP/2 Fingerprints on ADB-Exposed Android TVs

Kimwolf v7 Routes C2 via ENS and Hard-coded Tor Onion While Mimicking Chrome HTTP/2 Fingerprints on ADB-Exposed Android TVs

Kimwolf v7 decouples propagation from payload delivery and hardens C2 with ENS plus Tor while disguising HTTP/2 DDoS as Chrome traffic. The shift exposes a professionalized pipeline that offloads scanning and exploits initial access to separate operators. Detection now requires protocol-level fingerprint validation rather than simple traffic volume thresholds.

The malware dropped SystemService APKs that probe for root and execute libdevice.so ELF payloads, shifting from earlier Dirty COW x86 exploits to ADB-based propagation. Command-and-control now resolves through Ethereum RPC queries to ENS domains, falls back to edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd.onion, and routes everything through a local 127.0.0.1:23075 proxy. This tiered design removes scanning and brute-force code from the binary, indicating operators have outsourced initial access to external loaders.

⚡ Prediction

Unit 42: Kimwolf v7 will appear in at least three additional loader campaigns targeting port 5555 within 90 days of disclosure.

Sources (2)

  • [1]
    Primary Source(https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html)
  • [2]
    Supporting Source(https://unit42.paloaltonetworks.com/kimwolf-v7-analysis/)