ToxNetV2 LLM-assisted botnet controller
Malware Activity
Summary
Hide ▲
Show ▼
The ToxNetV2 botnet now uses an LLM-assisted controller that can turn host telemetry into operator-approved actions, expanding infected-system tasking to command execution, file writes, SSH, persistence, and compilation. The controller sends environment context to NVIDIA NIM with the z-ai/glm-5.2 model, parses the responses into structured tasks, and waits for operator approval before execution. The broader botnet also includes encrypted peer-to-peer C2, host management, scanner workers, self-propagation logic, and 17 network-attack launchers.
Related Happenings
LabubaRAT Rust RAT masquerading as NVIDIA software on Windows
Malware Activity
H score24
First: 14.07.2026 19:52
Last: 14.07.2026 19:52
Sources 1
About this happening:
A newly documented Rust-based RAT, LabubaRAT, now gives operators Windows host control with file movement, screenshot capture, and traffic proxying. The malware masq...
LabubaRAT Rust RAT masquerading as NVIDIA software on Windows
Malware ActivityAbout this happening: A newly documented Rust-based RAT, LabubaRAT, now gives operators Windows host control with file movement, screenshot capture, and traffic proxying. The malware masq...
Trojanized Pyrogram forks with hidden Telegram backdoor
Malware Activity
H score14
First: 01.07.2026 00:02
Last: 01.07.2026 00:02
Sources 1
About this happening:
Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...
Trojanized Pyrogram forks with hidden Telegram backdoor
Malware ActivityAbout this happening: Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...
MacOS.Gaslight Rust infostealer-backdoor with Telegram Bot API channel
Malware Activity
H score30
First: 24.06.2026 17:00
Last: 24.06.2026 17:00
Sources 1
About this happening:
Researchers identified macOS.Gaslight, a North Korea-linked Rust infostealer-backdoor that can steal Chrome, Brave, Firefox and Safari data, terminal histories, in...
MacOS.Gaslight Rust infostealer-backdoor with Telegram Bot API channel
Malware ActivityAbout this happening: Researchers identified macOS.Gaslight, a North Korea-linked Rust infostealer-backdoor that can steal Chrome, Brave, Firefox and Safari data, terminal histories, in...
Glassworm botnet command-and-control disruption
Malware Activity
H score10
First: 27.05.2026 17:00
Last: 27.05.2026 17:00
Sources 1
About this happening:
The Glassworm botnet had all four command-and-control channels disrupted, cutting operators off from infected machines and blocking new payload delivery. The infrastructur...
Glassworm botnet command-and-control disruption
Malware ActivityAbout this happening: The Glassworm botnet had all four command-and-control channels disrupted, cutting operators off from infected machines and blocking new payload delivery. The infrastructur...
RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations
Malware Activity
H score28
First: 25.05.2026 12:32
Last: 25.05.2026 12:32
Sources 1
About this happening:
The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...
RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations
Malware ActivityAbout this happening: The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...
Timeline
-
27.08.2026 18:12 2 articles · 4h ago
ToxNetV2 controller routes telemetry through NVIDIA NIM
Technical Analysis UpdateJoe Security said the AArch64 Linux ToxNetV2 botnet collects host and botnet telemetry, sends that context to NVIDIA NIM using the z-ai/glm-5.2 model, parses selected model responses into structured actions, and queues those actions for operator approval.
Show sources
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories — thehackernews.com — 27.08.2026 18:12
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories — thehackernews.com — 27.08.2026 18:12