securityonline.info 8/31/2026, 2:58:35 PM · external

ToxNetV2 botnet uses AI to scan and exploit Linux devices

ToxNetV2 botnet uses AI to scan and exploit Linux devices
CyberSIXT Evidence Panel
Primary Source joesecurity.org

THE ToxNetV2 botnet, recently discovered by Joe Security, integrates AI for malicious operations involving infected Linux systems. It utilizes a peer-to-peer architecture where both bot and controller roles are interchangeable, depending on network conditions. The central controller collects telemetry data and sends it to the GLM-5.2 AI model, which provides executable recommendations.

Notably, while the AI can suggest dangerous actions, final command execution requires human oversight, hence it’s not fully autonomous. ToxNetV2 has sophisticated functionalities, including scanning and exploiting vulnerabilities in devices, and comprises multiple modules for executing network attacks.

View Primary Source Via securityonline.info

Article by CyberSIXT