FBI: Beware of thieves building Androxgh0st botnets using stolen creds
ID: 31fd0d7a-b5a0-5813-80b8-576415136fbe
STIX ID: report--31fd0d7a-b5a0-5813-80b8-576415136fbe
Feed Name: The Register (Security)
Threat Score
The FBI and CISA warn that operators are exploiting long-patched vulnerabilities (CVE-2017-9841, CVE-2018-15133, CVE-2021-41773) to deploy Androxgh0st, a Python-based credential-stealing malware that scans for exposed .env files to harvest AWS, Office365, SendGrid, and Twilio credentials; attackers use these credentials to deploy web shells, execute remote code, and create AWS users/instances for further malicious activity, and the advisory includes IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
