CISA: AWS, Microsoft 365 Accounts Under Active 'Androxgh0st' Attack
ID: 0077beaa-16c8-5a95-af37-00d8815f006d
STIX ID: report--0077beaa-16c8-5a95-af37-00d8815f006d
Feed Name: Dark Reading
Threat Score
FBI and CISA warn of an active campaign using Python malware dubbed Androxgh0st to scan for Laravel .env files and exploit legacy PHP/Apache vulnerabilities (notably CVE-2017-9841 and CVE-2021-41773) to steal application credentials and deploy web shells; stolen keys have been used to create AWS users and instances and to access high-value services such as AWS, Microsoft 365, Twilio, and SendGrid.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
