{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/android-tv-box/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Android TV box","Android set-top box"],"_cs_severities":["high"],"_cs_tags":["iot","botnet","android","ddos"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eKimwolf v7 is the latest iteration of the Kimwolf (or AISURU) botnet, which specifically targets Android-based IoT devices such as TV boxes and set-top boxes. First identified in February 2026, this variant represents a significant hardening of the botnet's command-and-control (C2) and offensive capabilities. Kimwolf v7 utilizes the nghttp2 library to construct full browser fingerprints within HTTP/2 DDoS floods, making the traffic harder to distinguish from legitimate user activity.\u003c/p\u003e\n\u003cp\u003eThe botnet exhibits high resilience to takedowns by utilizing a multi-tier C2 infrastructure. This includes querying five hard-coded public Ethereum RPC endpoints to resolve C2 addresses via Ethereum Name Service (ENS), an operator-controlled RPC facade (eth.rpcuniverse.com), and a hard-coded Tor .onion hidden service as a secondary fallback. The malware employs a local proxy architecture to route traffic across both clearnet and Tor. The binary masks its process name as 'netd_service' to evade detection on compromised Android systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe botnet scans for unauthenticated Android Debug Bridge (ADB) ports (5555) on local networks, often utilizing residential proxy services to reach target devices.\u003c/li\u003e\n\u003cli\u003eThe malware is installed onto the device via the ADB session without requiring user authentication.\u003c/li\u003e\n\u003cli\u003eUpon execution, the binary renames its process to 'netd_service' to masquerade as a legitimate Android system daemon.\u003c/li\u003e\n\u003cli\u003eThe bot checks for its presence using a Unix domain socket '@n[redacted]boxv7' to ensure only a single instance remains active.\u003c/li\u003e\n\u003cli\u003eThe bot initiates C2 resolution by querying hard-coded public Ethereum RPC endpoints to resolve ENS domain records.\u003c/li\u003e\n\u003cli\u003eIf public resolution fails, the binary initiates a proxy state machine to connect to its hard-coded Tor hidden service.\u003c/li\u003e\n\u003cli\u003eThe bot maintains persistence through local boot receivers and awaits commands to initiate HTTP/2 DDoS floods or other malicious tasks.\u003c/li\u003e\n\u003cli\u003eDuring DDoS operations, the malware crafts HTTP/2 headers using spoofed browser fingerprints to evade rate-limiting and detection systems.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eKimwolf v7 primarily affects Android TV and set-top boxes, turning them into components of a high-resilience botnet used for large-scale DDoS attacks. The use of spoofed browser fingerprints increases the risk of successful traffic mitigation bypass, potentially overwhelming target services and causing significant infrastructure downtime. The botnet's reliance on residential proxy misuse also facilitates widespread, low-effort distribution across diverse networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all Android TV and set-top box devices on the network to ensure the Android Debug Bridge (ADB) is disabled on port 5555.\u003c/li\u003e\n\u003cli\u003eMonitor internal network traffic for unusual connections to public Ethereum RPC endpoints, particularly those attempting to resolve ENS-related queries from IoT/Android devices.\u003c/li\u003e\n\u003cli\u003eBlock or alert on connections to the known Tor hidden service: edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd.onion.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering for known C2 infrastructure IPs associated with the Kimwolf botnet, such as the 212.193.31.0/24 range.\u003c/li\u003e\n\u003cli\u003eDeploy endpoint security monitoring to detect process masquerading, specifically processes naming themselves 'netd_service' that were not spawned by the system init process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T10:25:58Z","date_published":"2026-08-11T10:25:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kimwolf-v7/","summary":"Kimwolf v7 is an evolved Android/IoT botnet that leverages unauthenticated ADB access, Ethereum Name Service (ENS) resolution, and HTTP/2 browser fingerprinting to perform resilient DDoS operations.","title":"Kimwolf v7 Botnet Evolution and Android IoT Targeting","url":"https://feed.craftedsignal.io/briefs/2026-08-kimwolf-v7/"}],"language":"en","title":"CraftedSignal Threat Feed - Android TV Box","version":"https://jsonfeed.org/version/1.1"}