unit42 · Crawled Jul 15, 2026
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
47 IoCs 1 Actors 3 Malware 4 CVEs
Read original article ↗
AI Summary
TuxBot v3 Evolution is a modular IoT botnet framework leveraging LLM-assisted development, capable of DDoS attacks, device infection via Telnet brute-forcing, and persistence across multiple architectures. The malware uses encrypted C2 communication with fallback mechanisms including DGA, P2P gossip, and IRC, though several components are non-functional due to development bugs. The operator is linked to the Keksec/Kaitori ecosystem, sharing infrastructure with known IoT threats, and has active C2 servers in Singapore and a dropper in Iceland.
AI-extracted · verify before operational use
Extracted Entities 8 found
Indicators of Compromise 47 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 209[.]182[.]237[.]133 | Details → |
| IP | 185[.]10[.]68[.]127 | Details → |
| IP | 154[.]6[.]197[.]43 | Details → |
| IP | 188[.]166[.]2[.]226 | Details → |
| Domain | c2[.]tuxbot[.]local | Details → |
| Domain | digikalas[.]online | Details → |
| Domain | jetross[.]com | Details → |
| Domain | cfcybernews[.]eu | Details → |
| Domain | captcha[.]kanfetka[.]site | Details → |
| SHA-256 | 71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d | Details → |
| SHA-256 | 6b7a8e0c96c2318e747f074f9a99d26738700769ac01bba692d19fc884847737 | Details → |
| SHA-256 | 146f6010f6ee082aab13e0148d39baefa77eaba4ff65817b511b08c2092bdfd2 | Details → |
| SHA-256 | bd6431fb06e4689142ef597cf00382e38ae20a5393a4d9277e45a3f5b3cbcff9 | Details → |
| SHA-256 | a03b0d41f5ef03328150331ffa0ed970998883f7e0343d79b2d3b95330d8e7c1 | Details → |
| SHA-256 | eb2fa179fde2f097c18d5d700ad87d660fc238ee14cbe5477032e60856859621 | Details → |
| SHA-256 | a8d70d16509e227d8306be361bc37a3dc9fe34bf476f51e361e55e6d293c2b3f | Details → |
| SHA-256 | 0f8bcca3ed65e980da2a1f90a767b7d543be32eeea3e9338d09d4d635a497988 | Details → |
| SHA-256 | 96b1f96efca3b9df2dea85678d60da27e3265b4a00e39e20e64b27bb985e1561 | Details → |
| SHA-256 | c7a36d6b8128c41f93a32413675401a10a2b5769b221bbaa8c5c309585b73ceb | Details → |
| SHA-256 | 246c97957651de568e61eba1abe572f0b0f960456209995d43d53a0d7cc494a1 | Details → |
| SHA-256 | 3ec016d637e4c9cd331edd2580a229621ad638e924a4aa29ac0342e9144ace19 | Details → |
| SHA-256 | 2f2c3551762c03da126e45dca6fc2f997c63f0f1bfc21fd0ceed680ac6f083ce | Details → |
| SHA-256 | 9cd5e7e3c8bad321ef6c3d47fe25b3b56e9487f703a7eeee52db4067e6bafe61 | Details → |
| SHA-256 | e3a5296e762e9ee16010399666441d663beeea956382e97cca032a6a5ad06811 | Details → |
| SHA-256 | f1efb78887bb8783d7781c07cd13b53c9c79ebe5baa81f335838d0a6e73dec7e | Details → |
| SHA-256 | f324a45fcd2a9db4e542c09486c21b08bc42d6bf76fbd5f17871090361b10815 | Details → |
| SHA-256 | 15c17dce89deccd5172285b2650de957918aa1157cde8e4633ae15dfe31f2711 | Details → |
| SHA-256 | 511d3ffb4091cbcc94571d9fb3102e8cb424c6e187d01d53ff12078d54929bda | Details → |
| SHA-256 | 6aa4034dc7a2858094ff4dc59af07d6fe31119591e41599bcc0f3d0b516ee734 | Details → |
| Filename | tuxbot.alpha | Details → |
| Filename | tuxbot.arm | Details → |
| Filename | tuxbot.arm64 | Details → |
| Filename | tuxbot.arm7 | Details → |
| Filename | tuxbot.hppa | Details → |
| Filename | tuxbot.m68k | Details → |
| Filename | tuxbot.mips | Details → |
| Filename | tuxbot.mips64 | Details → |
| Filename | tuxbot.mips64el | Details → |
| Filename | tuxbot.mipsel | Details → |
| Filename | tuxbot.ppc | Details → |
| Filename | tuxbot.ppc64le | Details → |
| Filename | tuxbot.riscv64 | Details → |
| Filename | tuxbot.s390x | Details → |
| Filename | tuxbot.sh4 | Details → |
| Filename | tuxbot.sparc64 | Details → |
| Filename | tuxbot.x86_64 | Details → |
| Filename | .bot_x86_64 | Details → |
MITRE ATT&CK TTPs 47 techniques
T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.004 Unix Shell · Execution T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1090.001 Internal Proxy · Command And Control T1090.002 External Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1090.004 Domain Fronting · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110.001 Password Guessing · Credential Access T1120 Peripheral Device Discovery · Discovery T1133 External Remote Services · Persistence T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1497 Virtualization/Sandbox Evasion · Defense Evasion T1498 Network Denial of Service · Impact T1498.001 Direct Network Flood · Impact T1543.001 Launch Agent · Persistence T1546.004 Unix Shell Configuration Modification · Privilege Escalation T1546.008 Accessibility Features · Privilege Escalation T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1572 Protocol Tunneling · Command And Control T1573 Encrypted Channel · Command And Control T1573.001 Symmetric Cryptography · Command And Control T1573.002 Asymmetric Cryptography · Command And Control T1573.003 T1573.003 T1573.004 T1573.004 T1588.002 Tool · Resource Development T1071 Application Layer Protocol · Command And Control T1078.001 Default Accounts · Defense Evasion T1220 XSL Script Processing · Defense Evasion T1659 Content Injection · Initial Access