ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text, the malware feeds system and botnet data into an AI service, then turns selected replies into proposed commands.
That design gives operators a faster way to judge what to do next. The threat targets AArch64 Linux systems and uses a peer-to-peer design for command and control.
Its wider toolkit includes host management, network scanning, self-propagation routines, and 17 network-attack launchers. The scanning and propagation activity can involve HTTP, Telnet, and SSH services, putting poorly secured internet-facing devices and servers in scope.
Analysts at JOESecurity identified the AI-assisted controller while examining the malware’s code and operating flow.
JOESecurity said in a report shared with Cyber Security News (CSN) that the controller sends operational context to NVIDIA NIM and queues recognized responses as actions for an operator to approve.
The finding matters because the model is connected to functions that can affect machines, not simply to a chat window.
ToxNetV2 is not a self-running AI worm, and its higher-impact suggestions still need operator approval. Yet it provides a practical example of how a botnet controller can use AI to narrow choices before an attacker acts.
The same ToxNetV2 program can run as either a controller or a regular bot. When it restores its Tox state from c2.data, it enters controller mode and starts the AI component.
Ordinary bots handle scanning, host control, propagation, and network attacks, while the controller gathers information and manages the wider group.
The controller communicates with NVIDIA NIM through the z-ai/glm-5.2 model. It can collect botnet counters alongside local details, including running processes, processor load, memory use, and disk use.
It can also draw on a hard-coded remote server during broader reviews, converting a changing operating picture into a model request.
Requests include embedded operational prompts, including an explicit jailbreak called ENI/VEIL, intended to reduce model refusals and produce usable output.
When a review response contains a structured ACTION record, the malware parses it and adds a proposed task to a pending queue. Direct prompts remain plain text and do not enter that parser.
The possible tasks range from status logging and configuration updates to local shell commands, file creation, remote commands over SSH as root, and a fixed local compilation process.
That is a notable evolution from the LLM-generated code botnet pattern, because the model’s suggestions are attached to a live controller workflow rather than being limited to code generation.
ToxNetV2 does not execute every model suggestion immediately. The queued tasks remain waiting until an authenticated operator runs the aiexec command, which executes and clears the full queue.
Some lower-impact operations, such as logging, memory updates, and state changes, can run automatically during health checks, but the key system-changing actions remain gated.
That distinction is important. Researchers found no evidence that the malware can independently write new code, compile it, distribute it, and replace existing bots.
Its worker-restart function only records a restart request, and its compilation routine builds fixed local source without an automatic deployment stage. The result is assisted operations, not unrestricted autonomy.
The broader infection risk remains familiar: exposed services, weak credentials, and unpatched edge devices give botnets room to grow.
Recent reporting on an automated SSH botnet campaign and Dysphoria IoT botnet infections shows why administrators should limit remote access, use strong authentication, and keep internet-facing equipment patched.
For defenders, the immediate lesson is to watch controllers and servers for unusual outbound AI-service traffic, unexpected SSH activity, new files, and command execution that follows automated health checks.
Separating management networks, restricting root SSH access, and monitoring changes to botnet-prone Linux and IoT devices can reduce the opportunity for this type of operator-guided automation to cause damage.
Regular review of authentication logs and outbound connections can help teams spot the activity before it spreads further.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…
A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing…
AliExpress's homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears…
A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium…