Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ToxNetV2's auto-propagation functionality is stated to exploit 14+ CVEs, including CVE-2017-17215. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
CVE-2013-7471 is included in the CVE indicators extracted from the ToxNetV2 analysis, alongside vulnerabilities used for auto-propagation. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
ToxNetV2's auto-propagation functionality is stated to exploit 14+ CVEs, including CVE-2018-10562. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
CVE-2018-7600 is included in the CVE indicators extracted from the ToxNetV2 analysis, alongside vulnerabilities used for auto-propagation. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
ToxNetV2's auto-propagation functionality is stated to exploit 14+ CVEs, including CVE-2021-36260. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
CVE-2016-20016 is included in the CVE indicators extracted from the ToxNetV2 analysis, alongside vulnerabilities used for auto-propagation. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
CVE-2015-2051 is included in the CVE indicators extracted from the ToxNetV2 analysis, alongside vulnerabilities used for auto-propagation. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
ToxNetV2's auto-propagation functionality is stated to exploit 14+ CVEs, including CVE-2014-8361. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
CVE-2020-10987 is included in the CVE indicators extracted from the ToxNetV2 analysis, alongside vulnerabilities used for auto-propagation. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
ToxNetV2's auto-propagation functionality is stated to exploit 14+ CVEs, including CVE-2018-10561. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
ToxNetV2's auto-propagation functionality is stated to exploit 14+ CVEs, including CVE-2022-30525. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
ToxNetV2's auto-propagation functionality is stated to exploit 14+ CVEs, including CVE-2024-3272. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
CVE-2017-17562 is included in the CVE indicators extracted from the ToxNetV2 analysis, alongside vulnerabilities used for auto-propagation. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
CVE-2016-10372 is included in the CVE indicators extracted from the ToxNetV2 analysis, alongside vulnerabilities used for auto-propagation. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
ToxNetV2's auto-propagation functionality is stated to exploit 14+ CVEs, including CVE-2024-3273. | ToxNetV2 is described as a Linux AArch64 peer-to-peer botnet that embeds an LLM in its controller decision loop. The same binary can operate as either a controller or an ordinary bot depending on the presence of the Tox state file c2.data.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Its wider toolkit includes host management, network scanning, self-propagation routines, and 17 network-attack launchers.
It can collect botnet counters alongside local details, including running processes, processor load, memory use, and disk use.
The threat targets AArch64 Linux systems and uses a peer-to-peer design for command and control.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux AArch64 P2P botnet with controller-mediated LLM-assisted task generation and operator approval. It collects host and botnet telemetry, submits it to an LLM through NVIDIA NIM, parses structured ACTION records, and can execute shell commands, write files, conduct root SSH checks, and compile/deploy payloads. It includes network-DDoS launchers, HTTP/Telnet/SSH scanning and propagation, exploitation of public-facing devices, persistence mechanisms, process killing/locking, and destructive wiping ('brick') functionality. The content states that it is not fully autonomous or self-modifying because operators approve high-impact actions.
AI-assisted Linux botnet targeting AArch64 systems. It uses peer-to-peer command and control, supports host management, network scanning, self-propagation, and multiple network-attack launchers. Its controller sends operational context to NVIDIA NIM, parses structured AI responses into queued actions, and allows an authenticated operator to approve execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.