Known Indicators of Compromise Associated with Androxgh0st Malware
ID: b953a221-8066-5595-89ff-2fd630bc3496
STIX ID: report--b953a221-8066-5595-89ff-2fd630bc3496
Feed Name: CISA Cybersecurity Advisories
Threat Score
**Executive summary:** The FBI and CISA alert that Androxgh0st is an actively used Python-based malware that builds botnets to scan and exploit PHPUnit, Laravel, and vulnerable Apache servers (exploiting CVE-2017-9841, CVE-2018-15133, CVE-2021-41773) to steal .env and cloud credentials, drop web shells, and deploy further scanning infrastructure; the advisory includes IOCs, MITRE ATT&CK mappings, detection recommendations, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
