Malware & Tooling · IoT / OT Attack

IoT Botnet Adds Fallback Control Paths

The useful clue here is not that another IoT botnet exists. It is that this one was built as a reusable platform, so blocking one command path or one device type does not meaningfully break it.

Unit 42 says TuxBot v3 Evolution is a previously undocumented modular framework with source code, binaries for 17 architectures, and exploit support for more than 30 IoT device families. Its bot agent brute-forces Telnet, then talks to command infrastructure over encrypted TCP with fallbacks through a domain generator, peer-to-peer gossip, IRC, DNS TXT queries, or HTTP polling.

That mix makes the botnet harder to suppress with a single blocklist or one cleanup play. It also shows why internet-exposed embedded devices with weak credentials and weak egress controls keep getting recycled into larger botnets.

2 sources · Jul 15

CVEs in this update

25 CVEs

15 critical · 6 high · 0 medium · 0 low

14 in CISA KEV · 24 with EPSS above 1%

Highest severity: CVE-2022-22947 · 10.0 CRITICAL

Highest EPSS: CVE-2023-1389 · 100%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

Part of the PlainSec briefing for 2026-07-15

Every edition of this story: IoT Botnet Adds Fallback Control Paths

More from today