Poking at the Flodrix Botnet
ID: 4ca412a3-e838-55d7-9ea3-7721b1dbd51f
STIX ID: report--4ca412a3-e838-55d7-9ea3-7721b1dbd51f
Feed Name: Censys Blog
Date Published: 2025-06-19
Date Updated: 2026-04-27
Author: Ivonne Francia; Mark Ellzey; Senior Security Researcher
Censys researchers analyzed Trend Micro's disclosure that CVE-2025-3248 (Langflow) is being exploited to install Flodrix, a Mirai-like botnet; by interacting with an online C2 (80.66.75.121) they observed exposed portmapper and NFS services, mounted an /nfs2 share containing ARM malware and scripts, and enumerated 745 hosts (mostly Boa web server–running cameras concentrated in Taiwan) actively mounting the C2—publishing file hashes and a host list.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
