Malware
Aisuru
Honeypot-aware variant of Mirai.
Indicators of Compromise 79
Domain 0xrpc[.]io Domain avax[.]rpcuniverse[.]com Domain c2[.]tuxbot[.]local Domain captcha[.]kanfetka[.]site Domain cfcybernews[.]eu Domain digikalas[.]online Domain edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd[.]onion Domain eth[.]llamarpc[.]com Domain eth[.]merkle[.]io Domain eth[.]rpcuniverse[.]com Domain ethereum-rpc[.]publicnode[.]com Domain fuckbriankrebs[.]com Domain jetross[.]com Domain rpcuniverse[.]com Filename .bot_x86_64 Filename libcow.so Filename libdevice.so Filename libn[redacted]kernel.so Filename libnkernel.so Filename tuxbot.alpha Filename tuxbot.arm Filename tuxbot.arm64 Filename tuxbot.arm7 Filename tuxbot.hppa Filename tuxbot.m68k Filename tuxbot.mips Filename tuxbot.mips64 Filename tuxbot.mips64el Filename tuxbot.mipsel Filename tuxbot.ppc Filename tuxbot.ppc64le Filename tuxbot.riscv64 Filename tuxbot.s390x Filename tuxbot.sh4 Filename tuxbot.sparc64 Filename tuxbot.x86_64 GitHub Repo MHDDoS MD5 036bcb62be72c4663b9564955f93b05f MD5 33faca1e0090f6b12eff703daf4606e4 MD5 d759364844d78a728505fb0485c3adbc SHA-256 0f8bcca3ed65e980da2a1f90a767b7d543be32eeea3e9338d09d4d635a497988 SHA-256 146f6010f6ee082aab13e0148d39baefa77eaba4ff65817b511b08c2092bdfd2 SHA-256 15c17dce89deccd5172285b2650de957918aa1157cde8e4633ae15dfe31f2711 SHA-256 246c97957651de568e61eba1abe572f0b0f960456209995d43d53a0d7cc494a1 SHA-256 2ec2e85b0358e0c681cb5067489a9086ec97dbbf7e3c952dd9cd496b319d5af5 SHA-256 2f2c3551762c03da126e45dca6fc2f997c63f0f1bfc21fd0ceed680ac6f083ce SHA-256 345222bca004595977f971d76900b0c65fd9bf9d91c50cd0c5bf5a93f1ad9e49 SHA-256 3ec016d637e4c9cd331edd2580a229621ad638e924a4aa29ac0342e9144ace19 SHA-256 406647de09a0ffa279756b4ccb344b1b76a333320c5b50fd367901fa006cf0ff SHA-256 511d3ffb4091cbcc94571d9fb3102e8cb424c6e187d01d53ff12078d54929bda SHA-256 6aa4034dc7a2858094ff4dc59af07d6fe31119591e41599bcc0f3d0b516ee734 SHA-256 6b7a8e0c96c2318e747f074f9a99d26738700769ac01bba692d19fc884847737 SHA-256 71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d SHA-256 951c94809aa6c7ab587125f9d4df30fa6a49ee0cbba76a4b7ceedaaa0e5dcd36 SHA-256 96b1f96efca3b9df2dea85678d60da27e3265b4a00e39e20e64b27bb985e1561 SHA-256 9cd5e7e3c8bad321ef6c3d47fe25b3b56e9487f703a7eeee52db4067e6bafe61 SHA-256 a03b0d41f5ef03328150331ffa0ed970998883f7e0343d79b2d3b95330d8e7c1 SHA-256 a8d70d16509e227d8306be361bc37a3dc9fe34bf476f51e361e55e6d293c2b3f SHA-256 bd6431fb06e4689142ef597cf00382e38ae20a5393a4d9277e45a3f5b3cbcff9 SHA-256 c7a36d6b8128c41f93a32413675401a10a2b5769b221bbaa8c5c309585b73ceb SHA-256 e3a5296e762e9ee16010399666441d663beeea956382e97cca032a6a5ad06811 SHA-256 eb2fa179fde2f097c18d5d700ad87d660fc238ee14cbe5477032e60856859621 SHA-256 f07821e313c16cbbd82def45094a22c8d474164051bdbc7648d6869e012014b4 SHA-256 f1efb78887bb8783d7781c07cd13b53c9c79ebe5baa81f335838d0a6e73dec7e SHA-256 f324a45fcd2a9db4e542c09486c21b08bc42d6bf76fbd5f17871090361b10815 SHA-256 f3e8a55a2a3ea7c7b6676e90f4f49a2c55b13065b68ee50c51cc35fe2b5c3237 IP 154[.]6[.]197[.]43 IP 185[.]10[.]68[.]127 IP 188[.]166[.]2[.]226 IP 1999 IP 209[.]182[.]237[.]133 IP 212[.]193[.]31[.]102 IP 212[.]193[.]31[.]119 IP 212[.]193[.]31[.]122 IP 212[.]193[.]31[.]158 IP 212[.]193[.]31[.]92 IP 2222 IP 23[.]94[.]221[.]104 IP 9999
MITRE ATT&CK TTPs 46
T1021.002 T1027 T1055 T1056.001 T1059 T1059.001 T1059.004 T1071 T1071.001 T1071.004 T1082 T1083 T1090 T1090.001 T1090.002 T1090.003 T1090.004 T1105 T1110.001 T1120 T1133 T1140 T1190 T1203 T1204.002 T1210 T1218.001 T1218.011 T1480 T1497 T1498 T1498.001 T1543.001 T1546.004 T1546.008 T1566 T1571 T1572 T1573 T1573.001 T1573.002 T1573.003 T1573.004 T1583 T1588 T1588.002
SMB/Windows Admin Shares
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
Keylogging
Collection
Command and Scripting Interpreter
Execution
PowerShell
Execution
Unix Shell
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
Internal Proxy
Command And Control
External Proxy
Command And Control
Multi-hop Proxy
Command And Control
Domain Fronting
Command And Control
Ingress Tool Transfer
Command And Control
Password Guessing
Credential Access
Peripheral Device Discovery
Discovery
External Remote Services
Persistence
Deobfuscate/Decode Files or Information
Defense Evasion
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Malicious File
Execution
Exploitation of Remote Services
Lateral Movement
Compiled HTML File
Defense Evasion
Rundll32
Defense Evasion
Execution Guardrails
Defense Evasion
Virtualization/Sandbox Evasion
Defense Evasion
Network Denial of Service
Impact
Direct Network Flood
Impact
Launch Agent
Persistence
Unix Shell Configuration Modification
Privilege Escalation
Accessibility Features
Privilege Escalation
Phishing
Initial Access
Non-Standard Port
Command And Control
Protocol Tunneling
Command And Control
Encrypted Channel
Command And Control
Symmetric Cryptography
Command And Control
Asymmetric Cryptography
Command And Control
T1573.003
T1573.004
Acquire Infrastructure
Resource Development
Obtain Capabilities
Resource Development
Tool
Resource Development
Source Articles
Kimwolf v7: An Evolution of the Kimwolf Botnet
Unit42 identified a new version (v7) of the Kimwolf Android/IoT botnet, which enhances DDoS capabilities and strengthens command-and-control (C2) resilience. The malware targets Android TV boxes and IoT devices via unsecured ADB ports, using HTTP/2-based DDoS floods that spoof browser fingerprints to mimic legitimate traffic. Its C2 infrastructure leverages Ethereum Name Service (ENS) resolution via public RPC endpoints, a suspected operator-controlled RPC facade, and a fallback to a hard-coded Tor .onion address, ensuring persistence against takedown attempts.
unit42 ·3w ago
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Palo Alto Networks Unit 42 discovered a new version of the Kimwolf/AISURU Android and IoT botnet, dubbed Kimwolf v7, in February 2026. This version enhances operational resilience by using HTTP/2-based DDoS floods that mimic legitimate browsing through complete browser fingerprints, making detection more difficult. It employs a tiered C2 infrastructure leveraging Ethereum Name Service (ENS), a hard-coded Tor .onion address, and a local proxy for traffic routing, while offloading initial access to external loaders and focusing on DDoS and proxy relay functions.
hacker-news ·3w ago
Aisuru Botnet Shifts from DDoS to Residential Proxies – Krebs on Security
The Aisuru botnet, initially known for launching massive DDoS attacks exceeding 30 terabits per second, has shifted its operations to support a residential proxy business by leveraging hundreds of thousands of compromised IoT devices. The botnet's operators have updated their malware to allow renting infected devices to proxy services, which are increasingly used for large-scale data scraping to feed AI training models. This shift has caused significant disruption to ISPs and raised concerns about abuse of residential proxies for cybercrime and unauthorized content scraping.
krebsonsecurity
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
TuxBot v3 Evolution is a newly identified IoT botnet framework showing signs of large language model (LLM)-assisted development, though with functional flaws due to incomplete code. The malware targets IoT devices using brute-force attacks and known vulnerabilities, featuring a modular architecture with multiple C2 mechanisms including encrypted TCP, DGA, IRC, DNS, and P2P. It is attributed to the Keksec ecosystem based on shared infrastructure with Kaitori v3.9 and AISURU, indicating it is part of a broader portfolio of IoT botnets.
hacker-news ·1mo ago
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution is a modular IoT botnet framework leveraging LLM-assisted development, capable of DDoS attacks, device infection via Telnet brute-forcing, and persistence across multiple architectures. The malware uses encrypted C2 communication with fallback mechanisms including DGA, P2P gossip, and IRC, though several components are non-functional due to development bugs. The operator is linked to the Keksec/Kaitori ecosystem, sharing infrastructure with known IoT threats, and has active C2 servers in Singapore and a dropper in Iceland.
unit42 ·1mo ago