logo

Known Indicators of Compromise Associated with Androxgh0st Malware

ID: b953a221-8066-5595-89ff-2fd630bc3496

STIX ID: report--b953a221-8066-5595-89ff-2fd630bc3496

Feed Name: CISA Cybersecurity Advisories

Threat Score
75/100

Date Published: 2024-01-12

Date Updated: 2026-04-19

Author: CISA

...
...

**Executive summary:** The FBI and CISA alert that Androxgh0st is an actively used Python-based malware that builds botnets to scan and exploit PHPUnit, Laravel, and vulnerable Apache servers (exploiting CVE-2017-9841, CVE-2018-15133, CVE-2021-41773) to steal .env and cloud credentials, drop web shells, and deploy further scanning infrastructure; the advisory includes IOCs, MITRE ATT&CK mappings, detection recommendations, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.