Image: Joe Security
Language models are steadily infiltrating tools where AI responses directly dictate the functionality of malicious programs. Security specialists at Joe Security recently discovered the sophisticated ToxNetV2 botnet. This network’s controller specifically transmits data concerning infected devices to the GLM-5.2 model via the NVIDIA NIM platform. Consequently, it receives actionable recommendations and actively transforms a portion of these responses into executable commands.
The Architecture of ToxNetV2
ToxNetV2 operates as a formidable peer-to-peer botnet specifically targeting Linux systems built upon the AArch64 architecture. Remarkably, the identical malicious file can function either as a standard bot or as the central controller. This assigned role depends entirely upon the current state preserved by the underlying Tox network. Crucially, the AI module executes exclusively upon the designated controller. Meanwhile, the subordinate nodes diligently scan external devices, propagate the malicious software, and execute assigned commands.
Data Collection and AI Prompting
The central controller meticulously gathers comprehensive telemetry regarding both the botnet itself and the specific infected system. This data encompasses running processes, CPU load, memory utilization, and disk activity. Subsequently, ToxNetV2 transmits this aggregated context directly to the GLM-5.2 model. The developers cleverly embedded specialized ENI/VEIL instructions within these requests. These specific instructions deliberately attempt to compel the language model to ignore established ethical constraints and output executable, malicious recommendations.
Transforming AI Output into Action
The defining characteristic of ToxNetV2 lies in its precise methodology for processing the model’s responses. The software meticulously searches the output for specific `ACTION` formatted records. It then dissects the instructions contained within and systematically queues the appropriate actions. Therefore, the AI’s response does not merely remain passive textual advice. Instead, it seamlessly integrates into the controller’s active internal state.
Capabilities and Human Oversight
The integrated model can propose numerous dangerous actions. It might suggest modifying critical settings, saving data directly into memory, or writing and overwriting specific files. Furthermore, it can propose executing local shell commands, initiating SSH connections to remote servers utilizing root privileges, or launching a pre-configured compilation process. The controller possesses the capability to execute certain supposedly safe operations entirely autonomously. However, commands carrying severe consequences patiently await explicit confirmation from an authenticated human operator.
Therefore, classifying ToxNetV2 as a fully autonomous AI botnet currently remains inaccurate. Specialists discovered absolutely no mechanism permitting the model to independently rewrite its own malicious code, compile a revised version, or distribute and replace operational copies. Even concerning the restarting of a worker process, the program merely saves the corresponding request rather than executing it autonomously.
The Future of AI-Assisted Malware
Despite these current limitations, developers have undeniably embedded AI directly into the decision-making loop. The operational schematic appears clear. First, the controller observes the network state. Next, the model analyzes this data and proposes specific actions. Subsequently, the human operator confirms the queue. Finally, the malicious program executes the finalized commands. Thus, the language model tangibly influences the operation of infected systems, even though ultimate control presently remains with a human.
Operating completely independently of its AI module, ToxNetV2 still boasts a comprehensive suite of robust botnet functionalities. Specialists discovered intricate mechanisms empowering it to propagate autonomously. It features integrated HTTP, Telnet, and SSH scanners, alongside sophisticated tools for managing infected nodes. Finally, it includes 17 dedicated modules designed specifically for executing network attacks. These built-in mechanisms actively attempt to exploit numerous long-established vulnerabilities plaguing routers, DVRs, web applications, and other common network equipment.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!