logo

FBI: Androxgh0st malware botnet steals AWS, Microsoft credentials

ID: 2fd580ae-675b-5dc6-89dd-cf62a17abffd

STIX ID: report--2fd580ae-675b-5dc6-89dd-cf62a17abffd

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-01-16

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA and the FBI warn of an active Androxgh0st botnet that scans for RCE vulnerabilities (notably CVE-2017-9841, CVE-2021-41773, CVE-2018-15133) to harvest .env files and steal cloud credentials (AWS, Twilio, SendGrid, Office365). Operators use stolen credentials to send spam, create backdoors and web shells, provision AWS instances to expand scanning, and deploy further malicious tools; agencies recommend patching, removing/revoking credentials from .env files, checking for unauthorized access, and scanning for suspicious PHP files and outbound requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.