logo

Poking at the Flodrix Botnet

ID: 4ca412a3-e838-55d7-9ea3-7721b1dbd51f

STIX ID: report--4ca412a3-e838-55d7-9ea3-7721b1dbd51f

Feed Name: Censys Blog

Threat Score
72/100

Date Published: 2025-06-19

Date Updated: 2026-04-27

Author: Ivonne Francia; Mark Ellzey; Senior Security Researcher

...
...

Censys researchers analyzed Trend Micro's disclosure that CVE-2025-3248 (Langflow) is being exploited to install Flodrix, a Mirai-like botnet; by interacting with an online C2 (80.66.75.121) they observed exposed portmapper and NFS services, mounted an /nfs2 share containing ARM malware and scripts, and enumerated 745 hosts (mostly Boa web server–running cameras concentrated in Taiwan) actively mounting the C2—publishing file hashes and a host list.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.