logo

FBI: Androxgh0st Malware Building Mega-Botnet for Credential Theft

ID: b434ecc8-d8e0-552c-b407-014322b0a848

STIX ID: report--b434ecc8-d8e0-552c-b407-014322b0a848

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-01-18

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

### Executive summary The FBI and CISA issued a joint advisory on AndroxGh0st, a malware family used to build a botnet for credential theft and backdoor access by exploiting web application/server vulnerabilities (notably PHPUnit/CVE-2017-9841, Apache CVE-2021-41773, and Laravel-related flaws) and harvesting exposed .env files containing cloud and service credentials; the advisory includes indicators of compromise and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.