Joe Security's Blog
Joe Reverser 2.1 Golden Eagle
We are proud to announce the release of Joe Reverser 2.1 “Golden Eagle”, the latest evolution of our agentic automated malware and phishing analyst.Joe Reverser is designed to help security analysts investigate complex malware, phishing campaigns, malicious documents, and web-based threats through autonomous analysis and reverse engineering. With Golden Eagle, we are expanding these capabilities even further and making Joe Reverser easier to integrate into automated analysis workflows.
Read more...
Joe Sandbox v45 - Green Opal
Today, we are proud to release Joe Sandbox 45 under the code name Green Opal! This release is packed with many new detection signatures and important features to improve Joe Sandbox.Our Joe Sandbox Cloud Pro, Basic, and OEM servers have recently been upgraded to Green Opal.If you wish to upgrade your on-premise Joe Sandbox installation, please follow the instructions in the chapter on "Updating" in the user guide which you find in our customer portal. 625 New Behavior and YARA SignaturesJoe Sandbox v45 comes with a significant number of new detection signatures.
Read more...
ToxNetV2: An AI-Assisted Botnet Controller
IntroductionToxNetV2 is an AArch64 Linux peer-to-peer botnet that integrates an LLM into the operational workflow of its controller. As uncovered in the Joe Reverser analysis, the controller collects host and botnet telemetry, sends that context to NVIDIA NIM, parses selected model responses into structured actions, and queues those actions for operator approval. The resulting workflow is straightforward: telemetry → LLM analysis → structured actions → operator approval → execution The system is not fully autonomous or self-modifying. The operator remains the final approval point for its higher-impact AI-generated actions.
Read more...