logo

New IoT Botnet Uses 1,496 Default Passwords and Seven Persistence Mechanisms

ID: e5a94270-b9c8-5e42-b6df-ee8b76ec04cd

STIX ID: report--e5a94270-b9c8-5e42-b6df-ee8b76ec04cd

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Varshini

...
...

**TuxBot v3 Evolution** is a modular IoT botnet framework that targets Linux-based and embedded devices using Telnet credential brute forcing (1,496 credential pairs), supports 17 CPU architectures, implements multiple persistence techniques and stealth checks, and provides encrypted C2 channels (X25519 + ChaCha20-Poly1305) along with DGA/DNS/P2P fallbacks; researchers observed active samples (VirusTotal, Jan 2026) and published IOCs including a SHA-256 hash.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.