logo

How Androxgh0st rose from Mozi's ashes to become 'most prevalent malware'

ID: 21021899-5488-5ffb-9483-b679360722d3

STIX ID: report--21021899-5488-5ffb-9483-b679360722d3

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2024-12-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Androxgh0st, a cloud credential-stealing botnet that has integrated Mozi IoT-infection capabilities, has rapidly expanded in late 2024 to target Windows, macOS, Linux systems, web servers, routers, firewalls, and other IoT devices by exploiting dozens of CVEs; Check Point reported it affected ~5% of organizations in November and security firms and US agencies warn of large-scale exploitation and suspected Chinese state-linked use for surveillance, theft, and DDoS operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.