logo

LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures

ID: e67ccd38-2795-56d2-8aba-6e5c904a6b12

STIX ID: report--e67ccd38-2795-56d2-8aba-6e5c904a6b12

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Mayura Kathir

...
...

TuxBot v3 is a modular, multi-architecture IoT botnet framework (C-based agents, Go C2) recovered by Unit 42 with source code, binaries and DDoS benchmark data; it supports brute-force Telnet/SSH/ADB scanning, multiple C2 channels (X25519/ChaCha20-Poly1305 encrypted TCP, DGA/DNS TXT, P2P, IRC/HTTP fallback) and a Go admin panel for multi-user DDoS-for-hire operations. Researchers observed live infrastructure and indicators (e.g., 185.10.68.127 dropper, 209.182.237.133:2222 C2, TCP ports 1999/2222/9999/1333), found LLM-generated code/comments that introduced functional bugs but left the bot ~70% operational, and warned that the recovered source makes it easy to repair and scale the threat unless IoT hygiene and monitoring are enforced.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.