Kimwolf v7: An Evolution of the Kimwolf Botnet

2026-08-17T20:51:31Z16f2654eb9c8430a0f0a474532ca6c6e44427d65373f5b4ac34ff9c5b316ea31
AI-assisted-attacksAPI-key-theftCI/CDDDoSENSEthereumGitHub ActionsICSIoTMFA-bypassOTPolygonTorXcodeblockchain-C2botnetcredential-theftidentity-attacksmacOSmalwarenpmpasskeyssoftware-supply-chainthreat-intelligencezero-day

What happened

Unit 42 threat intelligence feed covering malware and botnets, blockchain- and DNS-based command and control, npm and CI/CD supply-chain attacks, identity and passkey weaknesses, macOS developer malware, AI-assisted exploitation, webmail espionage, OT zero-days, and direct-IP communications. The collection includes high-impact threats affecting IoT, software development ecosystems, cloud credentials, enterprise identity, and industrial infrastructure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
16f2654eb9c8430a0f0a474532ca6c6e44427d65373f5b4ac34ff9c5b316ea31
Enrichment time
2026-08-17T20:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.