Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

unit42.paloaltonetworks+1securityaffairs+1unit42.paloaltonetworks+1Cybersecurity researchers at Palo Alto Networks have disclosed a previously undocumented IoT botnet framework called TuxBot v3 Evolution that was built with heavy assistance from a large language model — and shipped with the LLM's safety disclaimer still embedded in every source file.
Unit 42, Palo Alto Networks' threat intelligence team, published its findings on Monday, revealing a modular botnet framework capable of cross-compiling for 17 CPU architectures, from ARM and MIPS to PowerPC and RISC-V. The framework includes a C-based bot agent, a Go-based command-and-control server with a DDoS-for-hire panel, a custom exploit virtual machine, and Docker-based test infrastructure.unit42.paloaltonetworks
The researchers recovered the full source code, compiled binaries, and 254 automated DDoS benchmark reports, showing active development and testing into early 2026. The bot brute-forces Telnet access using 1,496 credential pairs and contains exploit code targeting more than 30 IoT device families.mallory+1
Unit 42 assessed the framework as "approximately 70% functional," with core capabilities — scanning, credential brute-forcing, persistence, encrypted C2 communication, and DDoS execution — all working. The parts that fail trace almost entirely to LLM-generated code the developer never reviewed.securityaffairs+1
The evidence of LLM involvement is extensive. Raw chain-of-thought reasoning was left verbatim in source file comments throughout the codebase, including lines like "// I created them so I should know?" and "// Wait, where is the command?" — an LLM narrating its own confusion, preserved in a working botnet. Every one of the roughly 60 C source files carries an identical header warning that "this code is for educational and authorized security research only."unit42.paloaltonetworks+1
The most consequential LLM failure sits in the C2 authentication module. The developer asked for Argon2id password hashing. The LLM could not import the correct library, fell back to SHA-256 loops resembling PBKDF2, but kept the Argon2id comments, constants, and output format intact — a hallucination shipped as production code.securityaffairs+1
An XOR key mismatch introduced during development breaks the IRC fallback C2 channel, four exploit payloads, and HTTP polling. A custom exploit virtual machine never fires because the Go compiler writes one file magic value while the C runtime expects another.unit42.paloaltonetworks
Unit 42 warned that the bugs are easy to correct. "We were able to fix these issues with a handful of LLM-assisted prompts," the researchers wrote, adding that six new production-compiled samples appeared in April 2026, suggesting a more polished version likely already exists.securityaffairs+1
Shared infrastructure links TuxBot to the Keksec ecosystem, a group known for running multiple IoT botnet variants in parallel. A dropper server on FlokiNET, an Iceland-based bulletproof hosting provider, serves both TuxBot payloads and Kaitori v3.9 binaries, while the developer's Git log leaked a hostname tied to an Iranian-hosted machine.unit42.paloaltonetworks+1
The development timeline stretches back to January 2025, when the developer cloned the open-source MHDDoS toolkit from GitHub. "A fully working version of this framework is not a theoretical concern, but a likely threat," Unit 42 concluded.unit42.paloaltonetworks