logo

Langflow Vulnerability Exploited to Deliver Flodrix Botnet (Campaign)

ID: 3f458170-68f4-5161-865c-f8bad5651d01

STIX ID: report--3f458170-68f4-5161-865c-f8bad5651d01

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2025-06-17

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report describes exploitation of CVE-2025-3248 in Langflow — an unauthenticated RCE in the code validation endpoint that allows execution of attacker-supplied Python — used to deliver downloader scripts and the Flodrix botnet. Flodrix, an evolution of the LeetHozer family, establishes TCP/UDP C2 channels, performs DDoS and resource hijacking, supports self-deletion and anti-debugging, and can parse encrypted C2 configs; multiple active downloaders and evolving samples indicate an ongoing campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.