logo

Androxgh0st Exploits SMTP Services To Extract Critical Data

ID: 4d78a3f2-c3ab-5fdc-a9b4-065c53579a5f

STIX ID: report--4d78a3f2-c3ab-5fdc-a9b4-065c53579a5f

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2024-03-20

Date Updated: 2026-04-22

Author: Eswar

...
...

AndroxGh0st is a multifunctional malware campaign targeting Laravel and related PHP/Apache vulnerabilities to execute arbitrary code, harvest credentials from .env files (AWS, Twilio, SendGrid), deploy PHP webshells and drop Linux miners; the report outlines exploited CVEs, malware capabilities (menu-driven checks and exploit options), and provides file-hash and IP indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.