Find notable cyber news and cases, enriched with sources, timelines, and signals.

ToxNetV2 LLM-assisted botnet controller

Malware Activity
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

The ToxNetV2 botnet now uses an LLM-assisted controller that can turn host telemetry into operator-approved actions, expanding infected-system tasking to command execution, file writes, SSH, persistence, and compilation. The controller sends environment context to NVIDIA NIM with the z-ai/glm-5.2 model, parses the responses into structured tasks, and waits for operator approval before execution. The broader botnet also includes encrypted peer-to-peer C2, host management, scanner workers, self-propagation logic, and 17 network-attack launchers.

Related Happenings

LabubaRAT Rust RAT masquerading as NVIDIA software on Windows

Malware Activity
H score24 First: 14.07.2026 19:52 Last: 14.07.2026 19:52 Sources 1

About this happening: A newly documented Rust-based RAT, LabubaRAT, now gives operators Windows host control with file movement, screenshot capture, and traffic proxying. The malware masq...

Trojanized Pyrogram forks with hidden Telegram backdoor

Malware Activity
H score14 First: 01.07.2026 00:02 Last: 01.07.2026 00:02 Sources 1

About this happening: Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...

MacOS.Gaslight Rust infostealer-backdoor with Telegram Bot API channel

Malware Activity
H score30 First: 24.06.2026 17:00 Last: 24.06.2026 17:00 Sources 1

About this happening: Researchers identified macOS.Gaslight, a North Korea-linked Rust infostealer-backdoor that can steal Chrome, Brave, Firefox and Safari data, terminal histories, in...

Glassworm botnet command-and-control disruption

Malware Activity
H score10 First: 27.05.2026 17:00 Last: 27.05.2026 17:00 Sources 1

About this happening: The Glassworm botnet had all four command-and-control channels disrupted, cutting operators off from infected machines and blocking new payload delivery. The infrastructur...

RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations

Malware Activity
H score28 First: 25.05.2026 12:32 Last: 25.05.2026 12:32 Sources 1

About this happening: The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...

Timeline

  1. 27.08.2026 18:12 2 articles · 4h ago

    ToxNetV2 controller routes telemetry through NVIDIA NIM

    Technical Analysis Update

    Joe Security said the AArch64 Linux ToxNetV2 botnet collects host and botnet telemetry, sends that context to NVIDIA NIM using the z-ai/glm-5.2 model, parses selected model responses into structured actions, and queues those actions for operator approval.

    Show sources