TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM).
Intelligence analysis by Llama

TuxBot v3 Evolution is a botnet framework that shows signs of being developed with assistance from a large language model (LLM). The framework consists of multiple components, including a C-based bot agent and a Go-based command-and-control (C2) server.
Imagine a computer program that can help create a special kind of malware that can take control of many devices at the same time. This program, called TuxBot v3 Evolution, is like a recipe book that helps the malware creator make a botnet. A botnet is like a team of robots that work together to do bad things on the internet.
Analysis
A $60B Vote of Confidence
The emergence of TuxBot v3 Evolution is a significant development in the world of cybersecurity, as it shows signs of being developed with assistance from a large language model (LLM). The framework consists of multiple components, including a C-based bot agent and a Go-based command-and-control (C2) server. The bot agent is designed to brute-force Telnet access on targeted devices with a set of 1,496 credential pairs, as well as incorporate exploit code targeting more than 30 IoT device families using known vulnerabilities.
The modular framework's lineage has been traced back to three different botnets, including Mirai, AISURU, and Wuhan. At least one sample of the malware was uploaded to the VirusTotal platform on January 20, 2026, indicating it has been around for over six months. Evidence suggests that work on the botnet commenced one year before that, when the author cloned the MHDDoS repository from GitHub.
The Go-based C2 server component uses three different TCP ports for incoming connections - TCP port 1999 (or 31337), which is used for handling encrypted command dispatch to connected bots, TCP port 2222, which presents an interactive shell for operators over SSH, and TCP port 9999, which uses a JSON interface for programmatic access. Once launched, the botnet follows a pre-defined initialization sequence to perform a series of actions, including loading the C2 address from a multi-tiered architecture, setting up anti-debugging and anti-VM protections, hiding its process name, installing persistence, launching various sub-modules to mount DDoS attacks, terminate competing processes, establish C2 channels over IRC, HTTP, DNS, and P2P, run scanners for Telnet, SSH, HTTP, and Android Debug Bridge (ADB), spawn a SOCKS5 proxy, and execute a cryptocurrency mining placeholder.
Multiple files contain raw LLM chain-of-thought reasoning left verbatim in comments. These comments are the LLM's internal reasoning as it worked through porting tasks. This reasoning is complete with self-interruptions, decisions, and references to 'the user' (meaning the developer who prompted the LLM). Although TuxBot v3 Evolution is a botnet under development, the core working functions, coupled with its reliance on AI, signal accelerated integration of features, at the same time enabling what looks to be single developer to come up with a multi-pronged toolset with multiple C2 channels, a custom exploit VM, and a Go-based DDoS-for-hire panel.
The disclosure follows the emergence of two other botnets named RustDuck and AryStinger, which have targeted routers, IP cameras, Android boxes, and poorly secured servers to co-opt them into a network built to render online services offline and conduct reconnaissance.
Key points
- TuxBot v3 Evolution is a botnet framework that shows signs of being developed with assistance from a large language model (LLM).
- The framework consists of multiple components, including a C-based bot agent and a Go-based command-and-control (C2) server.
- The bot agent is designed to brute-force Telnet access on targeted devices with a set of 1,496 credential pairs, as well as incorporate exploit code targeting more than 30 IoT device families using known vulnerabilities.
- The modular framework's lineage has been traced back to three different botnets, including Mirai, AISURU, and Wuhan.
- At least one sample of the malware was uploaded to the VirusTotal platform on January 20, 2026, indicating it has been around for over six months.
The development of TuxBot v3 Evolution highlights the growing trend of using large language models to develop malware, which could have significant implications for cybersecurity. However, the fact that the malware is still in the development stage and has not been successfully deployed suggests that it may not be as effective as its creators hope.
The emergence of TuxBot v3 Evolution is a significant development in the world of cybersecurity, as it shows signs of being developed with assistance from a large language model (LLM). The framework consists of multiple components, including a C-based bot agent and a Go-based command-and-control (C2) server. The bot agent is designed to brute-force Telnet access on targeted devices with a set of 1,496 credential pairs, as well as incorporate exploit code targeting more than 30 IoT device families using known vulnerabilities.



