New IoT Botnet Uses 1,496 Default Passwords and Seven Persistence Mechanisms
ID: e5a94270-b9c8-5e42-b6df-ee8b76ec04cd
STIX ID: report--e5a94270-b9c8-5e42-b6df-ee8b76ec04cd
Feed Name: Cyber Press
Threat Score
**TuxBot v3 Evolution** is a modular IoT botnet framework that targets Linux-based and embedded devices using Telnet credential brute forcing (1,496 credential pairs), supports 17 CPU architectures, implements multiple persistence techniques and stealth checks, and provides encrypted C2 channels (X25519 + ChaCha20-Poly1305) along with DGA/DNS/P2P fallbacks; researchers observed active samples (VirusTotal, Jan 2026) and published IOCs including a SHA-256 hash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
