unit42 · Crawled Jul 15, 2026

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

47 IoCs 1 Actors 3 Malware 4 CVEs
Read original article ↗

AI Summary

TuxBot v3 Evolution is a modular IoT botnet framework leveraging LLM-assisted development, capable of DDoS attacks, device infection via Telnet brute-forcing, and persistence across multiple architectures. The malware uses encrypted C2 communication with fallback mechanisms including DGA, P2P gossip, and IRC, though several components are non-functional due to development bugs. The operator is linked to the Keksec/Kaitori ecosystem, sharing infrastructure with known IoT threats, and has active C2 servers in Singapore and a dropper in Iceland.

AI-extracted · verify before operational use

Extracted Entities 8 found

Indicators of Compromise 47 extracted

Type Value Detail
IP 209[.]182[.]237[.]133 Details →
IP 185[.]10[.]68[.]127 Details →
IP 154[.]6[.]197[.]43 Details →
IP 188[.]166[.]2[.]226 Details →
Domain c2[.]tuxbot[.]local Details →
Domain digikalas[.]online Details →
Domain jetross[.]com Details →
Domain cfcybernews[.]eu Details →
Domain captcha[.]kanfetka[.]site Details →
SHA-256 71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d Details →
SHA-256 6b7a8e0c96c2318e747f074f9a99d26738700769ac01bba692d19fc884847737 Details →
SHA-256 146f6010f6ee082aab13e0148d39baefa77eaba4ff65817b511b08c2092bdfd2 Details →
SHA-256 bd6431fb06e4689142ef597cf00382e38ae20a5393a4d9277e45a3f5b3cbcff9 Details →
SHA-256 a03b0d41f5ef03328150331ffa0ed970998883f7e0343d79b2d3b95330d8e7c1 Details →
SHA-256 eb2fa179fde2f097c18d5d700ad87d660fc238ee14cbe5477032e60856859621 Details →
SHA-256 a8d70d16509e227d8306be361bc37a3dc9fe34bf476f51e361e55e6d293c2b3f Details →
SHA-256 0f8bcca3ed65e980da2a1f90a767b7d543be32eeea3e9338d09d4d635a497988 Details →
SHA-256 96b1f96efca3b9df2dea85678d60da27e3265b4a00e39e20e64b27bb985e1561 Details →
SHA-256 c7a36d6b8128c41f93a32413675401a10a2b5769b221bbaa8c5c309585b73ceb Details →
SHA-256 246c97957651de568e61eba1abe572f0b0f960456209995d43d53a0d7cc494a1 Details →
SHA-256 3ec016d637e4c9cd331edd2580a229621ad638e924a4aa29ac0342e9144ace19 Details →
SHA-256 2f2c3551762c03da126e45dca6fc2f997c63f0f1bfc21fd0ceed680ac6f083ce Details →
SHA-256 9cd5e7e3c8bad321ef6c3d47fe25b3b56e9487f703a7eeee52db4067e6bafe61 Details →
SHA-256 e3a5296e762e9ee16010399666441d663beeea956382e97cca032a6a5ad06811 Details →
SHA-256 f1efb78887bb8783d7781c07cd13b53c9c79ebe5baa81f335838d0a6e73dec7e Details →
SHA-256 f324a45fcd2a9db4e542c09486c21b08bc42d6bf76fbd5f17871090361b10815 Details →
SHA-256 15c17dce89deccd5172285b2650de957918aa1157cde8e4633ae15dfe31f2711 Details →
SHA-256 511d3ffb4091cbcc94571d9fb3102e8cb424c6e187d01d53ff12078d54929bda Details →
SHA-256 6aa4034dc7a2858094ff4dc59af07d6fe31119591e41599bcc0f3d0b516ee734 Details →
Filename tuxbot.alpha Details →
Filename tuxbot.arm Details →
Filename tuxbot.arm64 Details →
Filename tuxbot.arm7 Details →
Filename tuxbot.hppa Details →
Filename tuxbot.m68k Details →
Filename tuxbot.mips Details →
Filename tuxbot.mips64 Details →
Filename tuxbot.mips64el Details →
Filename tuxbot.mipsel Details →
Filename tuxbot.ppc Details →
Filename tuxbot.ppc64le Details →
Filename tuxbot.riscv64 Details →
Filename tuxbot.s390x Details →
Filename tuxbot.sh4 Details →
Filename tuxbot.sparc64 Details →
Filename tuxbot.x86_64 Details →
Filename .bot_x86_64 Details →

MITRE ATT&CK TTPs 47 techniques

T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.004 Unix Shell · Execution T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1090.001 Internal Proxy · Command And Control T1090.002 External Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1090.004 Domain Fronting · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110.001 Password Guessing · Credential Access T1120 Peripheral Device Discovery · Discovery T1133 External Remote Services · Persistence T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1497 Virtualization/Sandbox Evasion · Defense Evasion T1498 Network Denial of Service · Impact T1498.001 Direct Network Flood · Impact T1543.001 Launch Agent · Persistence T1546.004 Unix Shell Configuration Modification · Privilege Escalation T1546.008 Accessibility Features · Privilege Escalation T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1572 Protocol Tunneling · Command And Control T1573 Encrypted Channel · Command And Control T1573.001 Symmetric Cryptography · Command And Control T1573.002 Asymmetric Cryptography · Command And Control T1573.003 T1573.003 T1573.004 T1573.004 T1588.002 Tool · Resource Development T1071 Application Layer Protocol · Command And Control T1078.001 Default Accounts · Defense Evasion T1220 XSL Script Processing · Defense Evasion T1659 Content Injection · Initial Access