<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Android-Botnet on CuraSec</title><link>https://curasec.metacog.co.kr/tags/android-botnet/</link><description>Recent content in Android-Botnet on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 12 Aug 2026 11:57:00 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/android-botnet/index.xml" rel="self" type="application/rss+xml"/><item><title>Kimwolf v7 Android/IoT Botnet Camouflages HTTP/2 DDoS as Legit Traffic</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-kimwolf-v7-android-botnet-makes-http-2-ddos-traffic-look-lik/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-kimwolf-v7-android-botnet-makes-http-2-ddos-traffic-look-lik/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The HTTP/2 traffic-mimicry technique is worth understanding when reviewing WAF and CDN rate-limiting rules, but no enrichment signals (no KEV, no PoC, no active targeting) justify an immediate configuration change.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The botnet&amp;rsquo;s ability to blend DDoS volume into legitimate-looking HTTP/2 sessions is a detection gap worth scoping — review whether your traffic-analysis and DDoS-detection rules distinguish request-rate anomalies at the HTTP/2 stream level rather than relying on IP reputation alone.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Awareness item for the evolving DDoS evasion landscape; relevant background for the next DDoS-mitigation vendor review or business-continuity risk discussion, but no board-level action is warranted now.&lt;/li>
&lt;/ul></description></item></channel></rss>