We have been tracking botnet capabilities for a long time now (see links below) to understand how they operate, what capabilities can be derived from them, and what we need to pay particular attention to during threat-led tests. In addition, these findings are incorporated into the further development of the DRS score.
A new analysis of the Kimwolf v7 bot by PaloAlto's Unit 42 identified a few new attack modules that had not previously been present in IoT botnets: The most significant new feature in v7 is a new HTTP/2 attack_module to generate HTTP/2-based flood attack. What makes this unique is the integrated fingerprint obfuscation: The malware dynamically reconstructs complete browser fingerprints (including those for Google Chrome and Safari) along with authentic headers. As a result, the malicious DDoS traffic at the protocol and header levels almost perfectly mimics legitimate user behavior.
What does this mean for BlueTeams:
- completely bypass fingerprint-based detection (Ja4X) possible
- when combined with residential proxies, the bots are indistinguishable from browsers
- adapt and fine-tune HTTP/2 defenses to counter the new attack methods
References
- Tracking DDoS Botnets
https://blog.kybervandals.com/tracking_botnets/ - Layer-7 Bots capabilities (IoT vs PseudoBrowser vs Browser)
https://blog.kybervandals.com/layer-7-bots-explained-iot-vs-pseudobrowser-vs-browser/ - Rapid Proxy Rotation explained
https://blog.kybervandals.com/rapid-proxy-rotation-explained/ - Unit 42: Kimwolf v7: An Evolution of the Kimwolf Botnet
https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ - DDoS Resiliency Score
https://www.ddosresiliencyscore.org/
TLS-Obfuscation is part of our Avydos-Platform for 2 years now, you will find it below Stack-Attacks (Expert/Enterprise only), allowing you to test your own defense against these types of attacks.
- Avydos DDoS Threat Simulation and Automation Platform:
https://avydos.com/en/ - zeroBS DDoS Testing Services:
https://zero.bs/en/
Member discussion: