ToxNetV2 Linux Botnet Leverages NVIDIA AI to Automate Attacks
Key Takeaways ToxNetV2 is a new Linux botnet leveraging NVIDIA NIM AI to automate attack suggestions. The botnet targets AArch64 Linux systems, employing a peer-to-peer architecture for command and...
Key Takeaways
- ToxNetV2 is a new Linux botnet leveraging NVIDIA NIM AI to automate attack suggestions.
- The botnet targets AArch64 Linux systems, employing a peer-to-peer architecture for command and control.
- Its capabilities include host management, network scanning, self-propagation, and 17 distinct network attack launchers.
- While AI generates attack suggestions, human operators must approve high-impact actions, preventing full autonomy.
- The botnet propagates through poorly secured HTTP, Telnet, and SSH services.
A novel Linux botnet, dubbed ToxNetV2, has been identified, showcasing a significant evolution in how artificial intelligence can be integrated into offensive cyber operations. Unlike previous instances where AI might assist in code generation, ToxNetV2 feeds real-time system and botnet data into an AI service, specifically NVIDIA NIM, to generate actionable attack commands for operators. This design streamlines the decision-making process for threat actors, accelerating their ability to execute subsequent malicious activities.
Table Of Content
The botnet primarily targets AArch64 Linux systems and employs a peer-to-peer (P2P) architecture for its command and control (C2) infrastructure. Its extensive toolkit includes functionalities for host management, comprehensive network scanning, self-propagation mechanisms, and a suite of 17 different network attack launchers. Its propagation efforts often exploit vulnerable HTTP, Telnet, and SSH services, placing inadequately secured internet-facing devices and servers at considerable risk.
AI-Assisted Operations and NVIDIA NIM Integration
Researchers at JOESecurity said in a report that they uncovered the AI-assisted controller during an in-depth analysis of the malware’s code and operational workflow. The report highlights that the controller component of ToxNetV2 transmits operational context to NVIDIA NIM. It then processes the AI’s responses, queuing recognized suggestions as potential actions for an operator to review and approve.
This integration is particularly noteworthy because the AI model is directly linked to functions capable of impacting target machines, moving beyond mere conversational or text-based output. While ToxNetV2 is not a fully autonomous AI worm, and higher-impact suggestions still require human intervention, it represents a concrete example of how botnet controllers can leverage AI to refine attack options before execution.
ToxNetV2’s Dual Role and AI Workflow
The ToxNetV2 program is designed to operate in two distinct modes: as a controller or as a standard bot. When the malware restores its Tox state from the “c2.data” file, it activates controller mode and initializes its AI component. Regular bots are responsible for executing tasks such as scanning, host control, propagation, and network attacks, while the controller aggregates intelligence and manages the entire botnet collective.
The controller interacts with NVIDIA NIM via the z-ai/glm-5.2 model. It gathers various data points, including botnet statistics and local system details like running processes, CPU load, memory usage, and disk space. During broader assessments, it can also query a hard-coded remote server, translating dynamic operational scenarios into specific model requests.
These AI requests incorporate embedded operational prompts, including a deliberate “jailbreak” command, ENI/VEIL, designed to minimize model refusals and ensure the generation of actionable output. When the AI’s response includes a structured ACTION record, the malware parses it and adds the proposed task to a pending queue. Direct, unstructured prompts, however, are treated as plain text and bypass this parsing mechanism.
The range of potential tasks generated by the AI is extensive, encompassing status logging, configuration updates, local shell commands, file creation, remote SSH commands executed as root, and a predefined local compilation process. This capability marks a significant advancement beyond typical LLM-generated code botnets, as the model’s suggestions are directly integrated into a live controller workflow rather than being confined to code generation.
Human Oversight: A Critical Limitation
Crucially, ToxNetV2 does not automatically execute every suggestion from the AI model. The generated tasks are held in a pending queue, awaiting an authenticated operator to issue the “aiexec” command, which then executes and clears the entire queue. While some low-impact operations, such as logging, memory updates, and state changes, may run automatically during health checks, critical system-altering actions remain under human control.
Researchers found no evidence that the malware possesses the capability to independently write new code, compile it, distribute it, or replace existing bots. Its worker-restart function merely records a restart request, and its compilation routine builds fixed local source code without an automated deployment stage. This indicates an “assisted operations” model rather than unrestricted autonomy.
The broader risk of infection remains rooted in familiar vulnerabilities: exposed services, weak credentials, and unpatched edge devices continue to provide fertile ground for botnet expansion. Recent reports on automated SSH botnet campaigns and Dysphoria IoT botnet infections underscore the urgent need for administrators to restrict remote access, implement robust authentication measures, and ensure internet-facing equipment is consistently patched.
What You Should Do
- Monitor controllers and servers for unusual outbound traffic to AI services.
- Look for unexpected SSH activity, new file creations, and command executions following automated health checks.
- Isolate management networks from public-facing infrastructure.
- Strictly limit or disable root SSH access.
- Regularly audit and monitor changes to Linux and IoT devices prone to botnet infections.
- Implement strong, unique passwords and multi-factor authentication for all remote access services.
- Keep all internet-facing devices, operating systems, and software patched and up-to-date.
- Review authentication logs and outbound network connections frequently to detect suspicious activity early.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Network endpoint | 45.130.151[.]214:33445 | Embedded Tox bootstrap or relay endpoint classified as custom, actor-controlled infrastructure |
| Network endpoint | 45.130.151[.]214:443 | Embedded Tox bootstrap or relay endpoint classified as custom, actor-controlled infrastructure |
| URL | http://45.151.139[.]113/z0l1mxjm4mdl4jjfjf7sb2vdmv/kaf.sh | HTTP and Telnet propagation path used to retrieve and execute a shell script; payload was unavailable during analysis <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7dd37eca-e14-4128-8156-b59bda43195f/ToxNetV2-Linux-Botnet-Uses-NVIDIA-AI-to-Generate-Shell-and-Remote-SSH-Attack-Actions.pdf?AWSAccessKeyId=ASIA2F3EMEYEQ5PSHYGJ&Signature=NbaH4WJe9TVTmQdC7Gla0ZJIk%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEDaCXVzLWVhc3QtMSJHMEUCIEpIeur4Bj4Jij4j3MFTkdS%2BlA2sxRYXLX2FOg%2Fdxk3eAiEA4imYH%2FHlAbVMSOOWMug%2F4EP0aBO4HXcIQU%2FRuxNMWfAq8wQIBhABGgw2OTk3NTMzMDk3MDUiDIm3JXhXRlscdBmeeSrQBMtPPX8s4U57OUG1AJN%2F2kr2Z%2BxT2C4%2B7wxqay5UvTZIswDHmNbiMTA%2B%2BkqEKjEA2HfqAQQEdqP3WK6JII%2FKlMzCjbwUKStddPn6v5szvBrt796alRMBkG2ezqwK9WOV5LCc5tNihJPw0VHCCE8uWo5otdiiK3gxmvttg1vIo4b6hR2NJzwTiStVXajdGWNibnoiGB%2BZDFMaMjqDyvlEkkMuiXB2gO3pt6kxdcYgYlDhcSIjwyfv543u7u54pB8uPTlKsPvYNZsuyYt6WkqCVEIzyKI30MRdiXsMNeUz94pGT7EozDfqfteWHpJwxXM06cB0VhDhZh%2BoODL4uk8lx%2Faze5t%2FpP2pTT02396UoXfFPxMIdJxQsffiEAEMrXVKmiNFsBypkiJW80Ju7Z6FwaCfRGFuV2nUHL%2BQC0IpE0UfEPDnaEpX8CzkW3Co4Uf1fVDzclMrN%2BKqMWYPBCilA4S48ZgE1Bz%2FexlDHB0LaoSpKKcXg8G8ix%2BLZ
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.