ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a big language mannequin into its controller workflow to show botnet and host telemetry into proposed operational actions.
The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 mannequin output to controller-side features together with native shell execution, file writes, distant SSH instructions, persistent state modifications, and cross-compilation.
Evaluation revealed by Joe Reverser exhibits the malware just isn’t a completely autonomous, self-modifying botnet.
As an alternative, it makes use of an operator-gated mannequin: telemetry is collected, despatched for LLM evaluation, transformed into structured ACTION: information, queued as pending duties, and executed solely after an authenticated operator points the aiexec command.
That workflow locations human approval between AI-generated suggestions and higher-impact operations. Nevertheless, mannequin output can nonetheless in the end attain actual execution mechanisms.
The identical ToxNetV2 binary can reportedly perform both as an odd bot or because the botnet controller.
When the malware restores Tox state from a file named c2.knowledge, it enters controller mode and initializes its AI subsystem. With out that state, it operates as a typical bot.
This separates the botnet’s operational roles. Unusual nodes retain capabilities for scanning, propagation, host administration, and community assaults, whereas the controller coordinates the fleet and handles AI-assisted decision-making.
The LLM is due to this fact not embedded throughout each compromised host; it sits centrally the place controller and bot telemetry might be analyzed collectively.
The controller’s AI evaluation paths accumulate system and botnet info, corresponding to course of state, load common, reminiscence consumption, disk utilization, and botnet counters.
Broader evaluations can moreover incorporate info retrieved from a hard-coded distant server.
ToxNetV2 Linux Botnet
Joe safety Researchers mentioned that, the malware then sends that context to NVIDIA NIM utilizing embedded prompts, together with an ENI/VEIL jailbreak immediate designed to scale back mannequin refusals and return actionable responses.
Not all mannequin responses turn out to be executable actions. The aiprompt command, for instance, accepts arbitrary operator textual content and returns an odd textual response.
Nevertheless, automated workflows together with aifix, aistrategy, aidaily, and aiideas can parse responses containing ACTION: entries and remodel acknowledged information into pending controller actions.
These actions embody shell_cmd, which runs a model-supplied native shell command; write_file, which creates or overwrites native recordsdata; and ssh_check, which executes a model-supplied command remotely as root.
Different supported actions can retailer state, add log entries, difficulty operator alerts, save AI reminiscence, alter activity weights, and run a set compilation workflow.
Crucially, structured actions stay in a queue till an operator approves them by way of aiexec, which processes and clears the whole pending-action listing.
Some lower-impact operations, together with logging, reminiscence, and state dealing with, could also be processed routinely throughout well being evaluation.
This makes ToxNetV2 higher characterised as an AI-assisted operations layer than a hands-off autonomous agent.
The recovered code doesn’t set up an entire autonomous cycle wherein the mannequin writes malware, compiles it, deploys it, and replaces current bot situations.
Sure motion names additionally overstate what their handlers do. A restart_worker motion information a restart request reasonably than immediately restarting a course of.
Equally, the compile_deploy path compiles fastened native supply code into an output binary, however researchers didn’t get well an automatic distribution or redeployment stage.
The numerous discovering is narrower: ToxNetV2 inserts LLM interpretation into the trail between operational telemetry and privileged controller features.
The AI element operates inside a broader Tox-based structure that includes encrypted peer-to-peer command-and-control, propagation logic, scanning staff, host-control options, and 17 network-attack launchers.
The malware consists of 25 Tox bootstrap and relay information; 23 correspond to public Tox infrastructure, whereas two reference 45.130.151[.]214, which can be configured because the AI module’s root SSH goal entry.
HTTP and Telnet propagation routines try to retrieve and execute a shell script from 45.151.139[.]113, though the payload was unavailable throughout evaluation.
The overlap between the SSH endpoint and botnet infrastructure suggests the tackle is actor-controlled.
ToxNetV2 illustrates a consequential malware design sample: the LLM doesn’t provide capabilities the botnet lacks, however it helps interpret circumstances and advocate how current shell, SSH, file, and infrastructure-control features must be used.
IOCs
| Kind | Indicator |
|---|---|
| IP tackle and port | 45.130.151.214:33445 |
| IP tackle and port | 45.130.151.214:443 |
| URL | http://45.151.139[.]113/z0l1mxjm4mdl4jjfjf7sb2vdmv/kaf.sh |
Observe: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintentional decision or hyperlinking. Re-fang solely inside managed risk intelligence platforms corresponding to MISP, VirusTotal, or your SIEM.
★ Which Safety Instruments Ought to You Minimize? Rating Them on One Web page – Obtain the Inherited Safety Stack Information






