ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a big language mannequin into its controller workflow to show botnet and host telemetry into proposed operational actions.
The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 mannequin output to controller-side capabilities together with native shell execution, file writes, distant SSH instructions, persistent state adjustments, and cross-compilation.
Evaluation printed by Joe Reverser reveals the malware shouldn’t be a completely autonomous, self-modifying botnet.
As a substitute, it makes use of an operator-gated mannequin: telemetry is collected, despatched for LLM evaluation, transformed into structured ACTION: data, queued as pending duties, and executed solely after an authenticated operator points the aiexec command.
That workflow locations human approval between AI-generated suggestions and higher-impact operations. Nonetheless, mannequin output can nonetheless in the end attain actual execution mechanisms.
The identical ToxNetV2 binary can reportedly operate both as an extraordinary bot or because the botnet controller.
When the malware restores Tox state from a file named c2.knowledge, it enters controller mode and initializes its AI subsystem. With out that state, it operates as an ordinary bot.
This separates the botnet’s operational roles. Unusual nodes retain capabilities for scanning, propagation, host administration, and community assaults, whereas the controller coordinates the fleet and handles AI-assisted decision-making.
The LLM is subsequently not embedded throughout each compromised host; it sits centrally the place controller and bot telemetry will be analyzed collectively.

The controller’s AI evaluation paths acquire system and botnet data, comparable to course of state, load common, reminiscence consumption, disk utilization, and botnet counters.
Broader opinions can moreover incorporate data retrieved from a hard-coded distant server.
ToxNetV2 Linux Botnet
Joe safety Researchers stated that, the malware then sends that context to NVIDIA NIM utilizing embedded prompts, together with an ENI/VEIL jailbreak immediate designed to scale back mannequin refusals and return actionable responses.
Not all mannequin responses grow to be executable actions. The aiprompt command, for instance, accepts arbitrary operator textual content and returns an extraordinary textual response.
Nonetheless, automated workflows together with aifix, aistrategy, aidaily, and aiideas can parse responses containing ACTION: entries and remodel acknowledged data into pending controller actions.

These actions embody shell_cmd, which runs a model-supplied native shell command; write_file, which creates or overwrites native information; and ssh_check, which executes a model-supplied command remotely as root.
Different supported actions can retailer state, add log entries, concern operator alerts, save AI reminiscence, alter activity weights, and run a hard and fast compilation workflow.
Crucially, structured actions stay in a queue till an operator approves them by way of aiexec, which processes and clears the entire pending-action record.
Some lower-impact operations, together with logging, reminiscence, and state dealing with, could also be processed robotically throughout well being evaluation.
This makes ToxNetV2 higher characterised as an AI-assisted operations layer than a hands-off autonomous agent.
The recovered code doesn’t set up a whole autonomous cycle wherein the mannequin writes malware, compiles it, deploys it, and replaces present bot situations.
Sure motion names additionally overstate what their handlers do. A restart_worker motion data a restart request moderately than immediately restarting a course of.
Equally, the compile_deploy path compiles fastened native supply code into an output binary, however researchers didn’t recuperate an automatic distribution or redeployment stage.
The numerous discovering is narrower: ToxNetV2 inserts LLM interpretation into the trail between operational telemetry and privileged controller capabilities.
The AI element operates inside a broader Tox-based structure that includes encrypted peer-to-peer command-and-control, propagation logic, scanning staff, host-control options, and 17 network-attack launchers.
The malware consists of 25 Tox bootstrap and relay data; 23 correspond to public Tox infrastructure, whereas two reference 45.130.151[.]214, which can be configured because the AI module’s root SSH goal entry.
HTTP and Telnet propagation routines try to retrieve and execute a shell script from 45.151.139[.]113, though the payload was unavailable throughout evaluation.
The overlap between the SSH endpoint and botnet infrastructure suggests the tackle is actor-controlled.
ToxNetV2 illustrates a consequential malware design sample: the LLM doesn’t provide capabilities the botnet lacks, nevertheless it helps interpret circumstances and advocate how present shell, SSH, file, and infrastructure-control capabilities needs to be used.
IOCs
| Kind | Indicator |
|---|---|
| IP tackle and port | 45.130.151.214:33445 |
| IP tackle and port | 45.130.151.214:443 |
| URL | http://45.151.139[.]113/z0l1mxjm4mdl4jjfjf7sb2vdmv/kaf.sh |
Be aware: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintended decision or hyperlinking. Re-fang solely inside managed risk intelligence platforms comparable to MISP, VirusTotal, or your SIEM.
★ Which Safety Instruments Ought to You Reduce? Rating Them on One Web page – Obtain the Inherited Safety Stack Information









