AndroxGh0st Botnet Comes Up in CISA's Radar

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation have issued a warning regarding the deployment of the AndroxGh0st malware by threat actors. These actors are establishing a botnet for the purpose of "identifying and exploiting victims in targeted networks."

AndroxGh0st, a Python-based malware initially documented in December 2022, has served as inspiration for the creation of similar tools such as AlienFox, GreenBot (also known as Maintance), Legion, and Predator.

This cloud attack tool is proficient at infiltrating servers with known security vulnerabilities, gaining access to Laravel environment files, and lifting credentials for prominent applications like Amazon Web Services (AWS), Microsoft Office 365, SendGrid, and Twilio.

AndroxGh0st Abuses Several Vulnerabilities

The attackers leverage notable vulnerabilities like CVE-2017-9841 (PHPUnit), CVE-2021-41773 (Apache HTTP Server), and CVE-2018-15133 (Laravel Framework) as part of their weaponization strategy.

Researchers emphasized that AndroxGh0st possesses multiple features facilitating SMTP abuse, including scanning, exploiting exposed credentials and APIs, and deploying web shells. Particularly concerning for AWS, the malware not only scans and parses AWS keys but also has the capability to generate keys for brute-force attacks.

These capabilities make AndroxGh0st a formidable threat, enabling the download of additional payloads and the establishment of persistent access to compromised systems.

This development comes shortly after SentinelOne revealed a tool called FBot, employed by attackers to breach web servers, cloud services, content management systems (CMS), and SaaS platforms.

January 17, 2024
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.