FBI: Androxgh0st Malware Building Mega-Botnet for Credential Theft
ID: b434ecc8-d8e0-552c-b407-014322b0a848
STIX ID: report--b434ecc8-d8e0-552c-b407-014322b0a848
Feed Name: HackRead
Threat Score
### Executive summary The FBI and CISA issued a joint advisory on AndroxGh0st, a malware family used to build a botnet for credential theft and backdoor access by exploiting web application/server vulnerabilities (notably PHPUnit/CVE-2017-9841, Apache CVE-2021-41773, and Laravel-related flaws) and harvesting exposed .env files containing cloud and service credentials; the advisory includes indicators of compromise and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
