Gafgyt Malware Targeting Cloud Environments (Campaign)
ID: fbd7df01-59cb-518a-9268-379045f258c9
STIX ID: report--fbd7df01-59cb-518a-9268-379045f258c9
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-08-14
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Gafgyt (Bashlite) has a new variant targeting cloud-native environments by brute-forcing weak SSH credentials to load two in-memory binaries: an SSH scanner and an XMR cryptominer that uses GPU acceleration. The campaign prioritizes resource control by killing competing processes, alters system configuration (e.g., /etc/sysctl.conf), and removes logs/history to avoid detection; researchers observed cloud-specific usernames like "AWS" and "Azure" in brute-force attempts and recommend searching for indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
