TuxBot v3 Botnet Source Reveals LLM Chain-of-Thought

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Palo Alto Networks Unit 42 disclosed TuxBot v3 Evolution, an IoT botnet framework whose source code retains verbatim LLM chain-of-thought comments—including self-interruptions and references to 'the user'—but several functions fail to work correctly because the developer shipped the AI's safety disclaimer without removing it.
- The botnet spans a C-based agent cross-compiled for seven architectures (ARM, MIPS, MIPSEL, MIPS64, x86_64, PowerPC, RISC-V), a Go-based command-and-control server with a DDoS-for-hire panel, a custom exploit virtual machine, Docker-based test infrastructure, and an automated build system.
- TuxBot's agent brute-forces Telnet using 1,496 credential pairs and carries exploit code for 30+ IoT device families, with C2 fallback layers including a SHA512 domain generation algorithm, Ed25519-signed P2P gossip, IRC, DNS TXT queries, and HTTP polling over an encrypted TCP channel.
- Researchers traced the framework's lineage to the Mirai, AISURU, and Wuhan botnets, with partial functions ported from the open-source MHDDoS Python DDoS toolkit; at least one sample was uploaded to VirusTotal on January 20, 2026, indicating development began roughly a year earlier.
- Shared infrastructure with Kaitori v3.9 and AISURU tooling places the TuxBot operator inside the Keksec ecosystem, a group known for running multiple parallel IoT botnet variants—though Unit 42 notes the custom exploit system does not yet function in the recovered version.
- Researchers Chris Navarrete, Asher Davila, and Doel Santos say TuxBot exemplifies how a single developer using an LLM can produce a multi-pronged toolset with encrypted C2, a DGA, a modular exploit engine, and a Go-based DDoS-for-hire panel—accelerating feature integration even when the underlying components are still incomplete.
Why it matters: The leaked chain-of-thought comments give defenders an unusually clear window into AI-assisted malware development in practice, including the verbatim safety warnings the developer chose to ignore. Unit 42 warns more polished iterations may already be in the wild; with the TuxBot operator tied to the active Keksec ecosystem and a sample on VirusTotal since January 20, 2026, the disclosure exposes a working AI-augmented playbook rather than a theoretical threat.
Ask SkimNews




