logo

The Resurgence of IoT Malware: Inside the Mirai-Based Botnet Campaign

ID: e9c5ca3d-5b4b-54ba-96d4-89a30dab7433

STIX ID: report--e9c5ca3d-5b4b-54ba-96d4-89a30dab7433

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2025-08-22

Date Updated: 2026-04-27

...
...

FortiGuard Labs analyzed a stealthy malware campaign ("Gayfemboy") actively exploiting multiple command-injection and RCE vulnerabilities in consumer and enterprise network devices (DrayTek, TP‑Link, Raisecom, Cisco ISE) to deliver a UPX-packed ELF payload that implements persistence, sandbox evasion, process-killing, backdoor/C2 communications, and DDoS/coin-mining capabilities; the report provides technical behavior, C2 domains, exploited CVEs, and extensive IOCs to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.