Unit 42 says Kimwolf v7 has now split its infection path from its attack binary: the Android TV and IoT botnet keeps the DDoS/proxy payload in the visible malware, while scanning, exploitation, and brute-force behavior have moved to an external loader. The same build also sends HTTP/2 floods that mimic Chrome browser fingerprints, making the traffic harder to filter as junk.
In plain terms, the box that defenders see is mostly the weapon, not the break-in tool. The botnet uses Ethereum Name Service (ENS) lookups, a blockchain naming system, with a Tor hidden-service fallback and local proxy routing so its command path survives takedowns even if one address is disrupted.
For CDN, WAF, SOC, and ISP teams, the map changes: you may no longer get the usual scan or brute-force noise before the flood arrives, and browser-shaped HTTP/2 traffic can slip past filters tuned to obvious bot behavior. If your view is mostly at the edge, the compromise and the DDoS stage can now arrive as two separate events.