logo

Mozi Resurfaces as Androxgh0st Botnet: Unraveling The Latest Exploitation Wave

ID: 35347afe-207c-5908-8e05-74b6ed0ed295

STIX ID: report--35347afe-207c-5908-8e05-74b6ed0ed295

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2024-11-06

Date Updated: 2026-04-27

...
...

CloudSEK’s analysis reports that the Androxgh0st botnet (active since Jan 2024) is actively exploiting a wide range of web-application and IoT vulnerabilities—leveraging more than 20 CVEs and deploying Mozi IoT payloads—to gain persistent access; the report includes C2 logs, TTP examples, IoCs (IPs and MD5 hashes), affected products, and mitigation recommendations, with low-confidence attribution to Chinese-linked actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.