Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Ethereum

Kimwolf v7 Uses Ethereum ENS and HTTP/2 to Upgrade DDoS Attacks

1 reports · First detected 2026-08-14 · Last active 2026-08-14

Kimwolf is a botnet that marshals compromised devices to overwhelm targets with distributed denial-of-service, or DDoS, traffic. Its seventh iteration adds HTTP/2 capabilities designed to make malicious requests resemble connections from ordinary web browsers. That matters because closer imitation of legitimate browser behavior can complicate traffic filtering, raising the cost and difficulty of defending websites and online services against high-volume attacks.

A cybersecurity vendor said Kimwolf v7 can emulate browser fingerprints over HTTP/2 to conceal DDoS traffic. The malware also embeds Ethereum RPC nodes and queries the Ethereum Name Service, or ENS, to locate command-and-control servers. The blockchain-based setup gives operators a more seizure-resistant communications channel by reducing reliance on a single conventional domain or host. The available report did not identify the vendor or disclose a publication date, attack volume, financial losses or confirmed victims.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)