TuxBot v3 Evolution is a modular Internet of Things botnet framework designed to compromise exposed IoT and other Linux-based embedded devices and conscript them into distributed denial-of-service operations. The framework includes a multi-architecture bot component and a command-and-control backend with operator management features, and it has been assessed as an actively developed but partially unfinished platform. Its codebase shows lineage to Mirai- and AISURU-related botnet development and has been linked through shared infrastructure and tooling overlap to the broader Keksec ecosystem, although public reporting stops short of firm attribution to a specific named threat actor.
The malware’s core infection flow is functional. It scans for exposed Telnet, SSH, HTTP, and Android Debug Bridge services, attempts access using large sets of default and vendor credentials, and also contains exploit code aimed at more than 30 IoT device families. After compromise, it establishes persistence through multiple mechanisms, disguises its process name, and launches scanning, attack, and command-and-control subsystems. Reported persistence methods include service-based and scheduled-task style mechanisms as well as shell-profile modification and watchdog-style relaunch behavior.
TuxBot v3 Evolution uses encrypted TCP for its primary command-and-control channel and implements several resilience mechanisms for fallback communications, including a domain generation algorithm, peer-to-peer gossip, DNS TXT queries, IRC, and HTTP polling. Not all fallback channels were operational in the recovered version because of implementation defects, but the primary command-and-control path and several alternate mechanisms were reported to work. The framework supports cross-compilation for numerous processor architectures, enabling broad deployment across heterogeneous IoT environments.
Its primary operational purpose is DDoS. The framework advertises a large set of attack vectors, though only a smaller subset of handlers was confirmed to function in the analyzed build. In addition to flooding capabilities, reported bot features include anti-debugging and anti-virtualization checks, removal of competing malware, and optional proxy-related functionality. Public reporting indicates that data theft is not its main objective; the malware is oriented toward botnet operations and attack execution rather than information exfiltration.
Researchers also noted strong signs that substantial portions of the framework were developed with assistance from a large language model, including retained AI-style comments, safety disclaimers, and coding mistakes that left some modules broken. Despite these flaws, the working infection, persistence, command-and-control, scanning, brute-force, and DDoS capabilities make it a credible threat, and a corrected version would likely be significantly more dangerous.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Completely Broken (exploit VM magic mismatch, never executes): CVE-2007-3010 ... CVE-2025-34117 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
These were written and compiled into a single 10,694-byte exploit package that would add coverage for 13 CVEs (including CVE-2022-1388, CVE-2022-22965, CVE-2020-8515 and CVE-2022-44877) plus two non-CVE targets. The package fails because the Go compiler writes the file magic value as 0x54555845 ("TUXE") while the C VM expects 0x4558504C ("EXPL"). The package is rejected on load, and the exploit worker thread runs but fires nothing. | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Completely Broken (exploit VM magic mismatch, never executes): CVE-2007-3010 ... CVE-2025-34117 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
These were written and compiled into a single 10,694-byte exploit package that would add coverage for 13 CVEs (including CVE-2022-1388, CVE-2022-22965, CVE-2020-8515 and CVE-2022-44877) plus two non-CVE targets. The package fails because the Go compiler writes the file magic value as 0x54555845 ("TUXE") while the C VM expects 0x4558504C ("EXPL"). The package is rejected on load, and the exploit worker thread runs but fires nothing. | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Completely Broken (exploit VM magic mismatch, never executes): CVE-2007-3010 ... CVE-2025-34117 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Completely Broken (exploit VM magic mismatch, never executes): CVE-2007-3010 ... CVE-2025-34117 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
These were written and compiled into a single 10,694-byte exploit package that would add coverage for 13 CVEs (including CVE-2022-1388, CVE-2022-22965, CVE-2020-8515 and CVE-2022-44877) plus two non-CVE targets. The package fails because the Go compiler writes the file magic value as 0x54555845 ("TUXE") while the C VM expects 0x4558504C ("EXPL"). The package is rejected on load, and the exploit worker thread runs but fires nothing. | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
These were written and compiled into a single 10,694-byte exploit package that would add coverage for 13 CVEs (including CVE-2022-1388, CVE-2022-22965, CVE-2020-8515 and CVE-2022-44877) plus two non-CVE targets. The package fails because the Go compiler writes the file magic value as 0x54555845 ("TUXE") while the C VM expects 0x4558504C ("EXPL"). The package is rejected on load, and the exploit worker thread runs but fires nothing. | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Completely Broken (exploit VM magic mismatch, never executes): CVE-2007-3010 ... CVE-2025-34117 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Completely Broken (exploit VM magic mismatch, never executes): CVE-2007-3010 ... CVE-2025-34117 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Completely Broken (exploit VM magic mismatch, never executes): CVE-2007-3010 ... CVE-2025-34117 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Completely Broken (exploit VM magic mismatch, never executes): CVE-2007-3010 ... CVE-2025-34117 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
Exploited CVEs Implemented but never called at runtime: CVE-2013-7471 ... CVE-2026-5815 | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Unit 42 found a new IoT botnet framework called TuxBot v3 Evolution. The framework targets IoT devices at scale.
A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks.
A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
TuxBot uses seven methods, including a systemd service, cron jobs, and shell profile injection.
TuxBot uses seven methods, including a systemd service, cron jobs, and shell profile injection.
Meanwhile, stealth code mimics common daemon names and relocates the binary across 21 directories.
These modules support distributed denial-of-service (DDoS) attacks, terminate competing malware
First, the bot scans random public addresses for open Telnet, SSH, HTTP, and ADB services.
These include a SHA-512 DGA, P2P gossip with signed commands, IRC, DNS TXT queries, and HTTP polling.
For communication, the malware relies on an encrypted TCP channel and incorporates multiple fallback mechanisms... DNS TXT queries, and HTTP polling. | These modules support distributed denial-of-service (DDoS) attacks, terminate competing malware, establish communications through IRC, HTTP, DNS, and P2P channels
For communication, the malware relies on an encrypted TCP channel and incorporates multiple fallback mechanisms... DNS TXT queries
These modules support distributed denial-of-service (DDoS) attacks... deploy a SOCKS5 proxy
These include a SHA-512 DGA, P2P gossip with signed commands, IRC, DNS TXT queries, and HTTP polling.
These include a SHA-512 DGA, P2P gossip with signed commands, IRC, DNS TXT queries, and HTTP polling.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IoT botnet framework focused on compromising internet-exposed devices via Telnet brute-force and additional SSH, HTTP, and ADB scanning, then maintaining persistence and launching DDoS attacks through encrypted and fallback C2 channels.
A modular IoT botnet framework with a C-based bot agent, Go-based C2 server, DDoS-for-hire panel, and exploit virtual machine. It brute-forces Telnet credentials, exploits over 30 IoT device families, uses encrypted C2 communications with DGA and peer-to-peer fallback, and includes anti-debugging, persistence, and attack modules.
A modular AI-assisted IoT botnet framework that cross-compiles bot agents for 17 architectures, brute-forces Telnet with 1,496 credential pairs, scans via Telnet/SSH/HTTP/ADB, targets more than 30 IoT device families, and supports DDoS operations through a Go-based C2 and exploit framework.
A modular IoT botnet framework targeting exposed Linux-based devices such as routers and cameras. It spreads via Telnet password guessing, SSH scanning, HTTP probing, ADB scanning, and exploitation attempts; supports many CPU architectures; uses encrypted C2 with fallback mechanisms; establishes persistence; removes rival malware; and conducts UDP, TCP, and DNS flooding for managed DDoS operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.