Palo Alto Networks Unit 42 Uncovers Kimwolf v7 Botnet Infecting Android Set-Top Boxes via Open ADB
Specialists from Palo Alto Networks Unit 42 have discovered Kimwolf v7, a new version of a botnet that infects Android set-top boxes and other IoT devices. The malware now mimics real browser behavior during DDoS attacks and hides its command infrastructure behind multiple layers of protection.
The main innovation is HTTP/2 flooding that uses full browser fingerprints. The malicious code reproduces characteristic protocol parameters and headers, making it significantly harder to distinguish attack traffic from actions of ordinary visitors. Instead of simply overwhelming a site with requests, the botnet carefully impersonates a crowd of legitimate users.
Developers have also strengthened communication with command servers. Kimwolf v7 obtains their addresses through Ethereum Name Service and public Ethereum RPC services. If this channel fails, a reserve address in the Tor network is hardcoded into the binary. All traffic passes through a local proxy that handles both regular internet and Tor connections equally.
The new version removes scanning, vulnerability exploitation, and password brute-forcing functions. Researchers believe operators have split responsibilities: an external loader handles infection, while Kimwolf focuses on DDoS attacks and traffic forwarding. Instead of the previous 43 commands, the botnet now uses 15 numbered methods, including a high-performance UDP flood optimized for ARM processors in Android set-top boxes.
Kimwolf has been attacking such devices at least since August 2025. Operators typically reach set-top boxes with open Android Debug Bridge on port 5555 through residential proxies. After launch, the malware disguises itself as system processes such as netd_service. Researchers also found APK files named SystemService that check for root access and execute an embedded ELF payload.
Unit 42 recommends treating Android set-top boxes as untrusted devices, isolating them from corporate networks, and disabling ADB or restricting access to USB only. An inexpensive box connected to a television can easily become a costly problem for the entire infrastructure.
Related articles
Leaked DarkSword iOS Exploit Chain 'P7' Now Steals Crypto Wallet Seeds and Keystores
A third build of the P7 variant of the leaked DarkSword iOS exploit chain has been identified, featuring a new lure site themed around Chinese online casinos and a fresh command server. The chain exploits six vulnerabilities, including three zero-days, to deploy an implant that decrypts the keychain directly on the device and extracts seed phrases from wallets such as imToken, Trust Wallet, and Phantom. Unlike the original GHOSTBLADE, P7 rewrites the C2 agent to focus exclusively on wallet data while retaining the core TaskRop and MIG-filter bypass modules. Passive analysis of public sources also uncovered the long-running 'qqtime' delivery cluster that pairs DarkSword with the older Coruna chain for broader iOS coverage. The operator uses channel codes to support multiple affiliate distributors and employs an AppleKeyStore oracle to decrypt keychain items locally before exfiltration.
Censys Exposes DarkSword iOS Exploit Platform and Coruna Crypto Wallet Stealer
Censys has disclosed the inner workings of DarkSword, a commercial platform that sells remote access to iOS devices, along with its associated malware Coruna that targets cryptocurrency wallet recovery keys. The infrastructure was exposed between September 15 and 17, allowing researchers to analyze the full attack chain starting from a WebKit and JavaScriptCore exploit delivered through the browser. After escaping the Safari sandbox and reaching the kernel, the platform deploys three layers including a flag, controller, and main implant. Coruna then scans the device for BIP39-compliant seed phrases stored in photos and Apple Notes across 19 targeted wallet applications such as MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, Bitpie, and BitKeep. The exposed server contained 11 victim recovery keys, 179 directories of extracted data, and 75 operator accounts, indicating a structured commercial operation with agent accounts, commissions, and device quotas. Confirmed infections affect devices running iOS 16.1 and 16.3.1, while Apple has extended patches to additional iOS 18 devices. Maintaining updated iOS versions remains the primary defense against this threat.
How Malware Evades Sandboxes: Detection Techniques and Defense Strategies
Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.
Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers
Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.