Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Inside an IoT Botnet Framework With LLM-Assisted Development

37.32.24.195

TLP:CLEAR
Active

IPv4 Address

Description

A previously undocumented modular IoT botnet framework has been identified with code partially generated using large language models. The framework consists of C-based bot agents compiled for 17 architectures, a Go-based command-and-control server with DDoS-for-hire panel, and custom exploit capabilities. Bot agents brute-force Telnet access using 1,496 credential pairs and target over 30 IoT device families. While core infection mechanisms function properly, several features are broken due to LLM-generated bugs that were shipped without manual review. The framework includes multiple fallback C2 mechanisms including domain generation algorithms, peer-to-peer gossip, IRC, and DNS TXT queries. Infrastructure analysis links this operation to the Keksec ecosystem through shared dropper servers. Development timeline spans from January 2025 to April 2026, with active C2 infrastructure observed since March 2026.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Inside an IoT Botnet Framework With LLM-Assisted Development
Pattern Type
STIX
Confidence
75%
Valid From
Jul 15, 2026 16:00
Total Sightings
0
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 37.32.24.195

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.