Malware · 61 days ago
IoT Botnet Adds Fallback Control Paths The useful clue here is not that another IoT botnet exists. It is that this one was built as a reusable platform, so blocking one command path or one device type does not meaningfully break it.
Unit 42 says TuxBot v3 Evolution is a previously undocumented modular framework with source code, binaries for 17 architectures, and exploit support for more than 30 IoT device families. Its bot agent brute-forces Telnet, then talks to command infrastructure over encrypted TCP with fallbacks through a domain generator, peer-to-peer gossip, IRC, DNS TXT queries, or HTTP polling.
That mix makes the botnet harder to suppress with a single blocklist or one cleanup play. It also shows why internet-exposed embedded devices with weak credentials and weak egress controls keep getting recycled into larger botnets.
CVEs in this update
25 CVEs
15 critical · 6 high · 0 medium · 0 low
14 in CISA KEV · 24 with EPSS above 1%
Highest severity: CVE-2022-22947 · 10.0 CRITICAL
Highest EPSS: CVE-2023-1389 · 100%
Showing the top 10 by KEV, EPSS, and severity.
Timeline Jul 15 Reported by The Hacker News Oct 9 CISA federal deadline for CVE-2014-8361 passedMay 22 CISA federal deadline for CVE-2023-1389 passedFeb 7 CISA federal deadline for CVE-2022-44877 passedJun 6 CISA federal deadline for CVE-2022-30525 passedMay 31 CISA federal deadline for CVE-2022-1388 passedMay 3 CISA federal deadline for CVE-2020-8515 passedApr 25 CISA federal deadline for CVE-2022-22965 passedApr 21 CISA federal deadline for CVE-2018-10562 passedSources 2 sources covering this story
Part of the PlainSec briefing for 2026-07-16
Editions Related stories
Malware · 61 days ago
IoT Botnet Adds Fallback Control Paths The useful clue here is not that another IoT botnet exists. It is that this one was built as a reusable platform, so blocking one command path or one device type does not meaningfully break it.
Unit 42 says TuxBot v3 Evolution is a previously undocumented modular framework with source code, binaries for 17 architectures, and exploit support for more than 30 IoT device families. Its bot agent brute-forces Telnet, then talks to command infrastructure over encrypted TCP with fallbacks through a domain generator, peer-to-peer gossip, IRC, DNS TXT queries, or HTTP polling.
That mix makes the botnet harder to suppress with a single blocklist or one cleanup play. It also shows why internet-exposed embedded devices with weak credentials and weak egress controls keep getting recycled into larger botnets.
CVEs in this update
25 CVEs
15 critical · 6 high · 0 medium · 0 low
14 in CISA KEV · 24 with EPSS above 1%
Highest severity: CVE-2022-22947 · 10.0 CRITICAL
Highest EPSS: CVE-2023-1389 · 100%
Showing the top 10 by KEV, EPSS, and severity.
Timeline Jul 15 Reported by The Hacker News Oct 9 CISA federal deadline for CVE-2014-8361 passedMay 22 CISA federal deadline for CVE-2023-1389 passedFeb 7 CISA federal deadline for CVE-2022-44877 passedJun 6 CISA federal deadline for CVE-2022-30525 passedMay 31 CISA federal deadline for CVE-2022-1388 passedMay 3 CISA federal deadline for CVE-2020-8515 passedApr 25 CISA federal deadline for CVE-2022-22965 passedApr 21 CISA federal deadline for CVE-2018-10562 passedSources 2 sources covering this story
Part of the PlainSec briefing for 2026-07-16
Editions Related stories