Mozi Resurfaces as Androxgh0st Botnet: Unraveling The Latest Exploitation Wave
ID: 35347afe-207c-5908-8e05-74b6ed0ed295
STIX ID: report--35347afe-207c-5908-8e05-74b6ed0ed295
Feed Name: CloudSEK Blog
Threat Score
CloudSEK’s analysis reports that the Androxgh0st botnet (active since Jan 2024) is actively exploiting a wide range of web-application and IoT vulnerabilities—leveraging more than 20 CVEs and deploying Mozi IoT payloads—to gain persistent access; the report includes C2 logs, TTP examples, IoCs (IPs and MD5 hashes), affected products, and mitigation recommendations, with low-confidence attribution to Chinese-linked actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
