Linux Botnet Uses NVIDIA NIM to Turn Host Telemetry Into Actionable Attack Commands
ID: f1d2f3bc-f5c9-51c8-837d-9c1944667839
STIX ID: report--f1d2f3bc-f5c9-51c8-837d-9c1944667839
Feed Name: Cyber Press
Threat Score
ToxNetV2 is an AArch64 Linux peer-to-peer botnet that embeds an NVIDIA NIM LLM in its controller to analyze host and botnet telemetry and generate structured ACTION tasks (including shell commands, file writes, SSH checks, and compilation). The AI-generated tasks are queued for operator approval via aiexec while regular bots perform scanning, propagation, and attacks; researchers recovered IOCs including 45.130.151.214 and 45.130.151.214:33445.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
