← Back to Crime & Security

Researchers Identify LLM-Assisted Development in New IoT Botnet Framework

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

LONDON (July 15, 2026) — Cybersecurity researchers disclosed details on Tuesday regarding TuxBot v3 Evolution, a new Internet of Things botnet framework developed by the group known as Keksec. The disclosure highlights unusual indicators within the malware's code suggesting it was constructed with significant assistance from large language models.

TuxBot has long been recognized for targeting Linux-based embedded devices, including routers and webcams. However, this latest iteration marks a shift in development methodology. Analysts examining the framework noted distinct patterns consistent with generative AI tools used to write or refactor code segments. These indicators include repetitive coding structures and specific syntax choices often associated with automated generation rather than traditional manual programming.

Despite the advanced appearance of certain modules, researchers found that several core components within TuxBot v3 Evolution appear non-functional. Critical sections responsible for command-and-control communication and payload delivery contain logical errors or incomplete logic gates that prevent them from operating as intended in a live environment. This suggests the framework may be an experimental build or a proof-of-concept rather than a fully operational weapon ready for deployment.

The developer behind TuxBot remains linked to the broader Keksec ecosystem, a network previously associated with various distributed denial-of-service campaigns and data exfiltration attempts against infrastructure targets. The emergence of this new version raises questions about whether the group is testing AI-driven development pipelines to accelerate malware creation or if these errors represent an attempt to mislead defenders.

Security firms analyzing the code have not yet observed TuxBot v3 Evolution being used in active attacks on public networks. However, the presence of non-functional components alongside sophisticated structural elements indicates a complex state of readiness that is difficult to categorize definitively as either dormant or operational.

The disclosure comes at a time when cybersecurity professionals are increasingly monitoring how artificial intelligence tools lower the barrier to entry for creating malicious software. The integration of LLM-assisted development into botnet frameworks could allow threat actors to rapidly iterate on code, potentially bypassing traditional detection methods that rely on known signatures and human coding habits.

Questions remain regarding the timeline for a fully functional release of TuxBot v3 Evolution. It is unclear whether the non-functional components are intentional placeholders or if they result from errors introduced during AI-assisted generation. Researchers continue to monitor traffic patterns associated with Keksec infrastructure to determine if this framework will be deployed in upcoming campaigns against IoT devices globally.

Discussion

0 / 2000