We have been tracking botnet capabilities for a long time now (see links below) to understand how they operate, what capabilities can be derived from them, and what we need to pay particular attention to during threat-led tests. In addition, these findings are incorporated into the further development of the DRS score.

A new analysis of the Kimwolf v7 bot by PaloAlto's Unit 42 identified a few new attack modules that had not previously been present in IoT botnets: The most significant new feature in v7 is a new HTTP/2 attack_module to generate HTTP/2-based flood attack. What makes this unique is the integrated fingerprint obfuscation: The malware dynamically reconstructs complete browser fingerprints (including those for Google Chrome and Safari) along with authentic headers. As a result, the malicious DDoS traffic at the protocol and header levels almost perfectly mimics legitimate user behavior.

What does this mean for BlueTeams:

  • completely bypass fingerprint-based detection (Ja4X) possible
  • when combined with residential proxies, the bots are indistinguishable from browsers
  • adapt and fine-tune HTTP/2 defenses to counter the new attack methods


References


TLS-Obfuscation is part of our Avydos-Platform for 2 years now, you will find it below Stack-Attacks (Expert/Enterprise only), allowing you to test your own defense against these types of attacks.