logo

Gafgyt Malware Variant Exploits GPU Power and Cloud Native Environments

ID: 489ad88f-0228-5e71-8523-6cfa26bb8caa

STIX ID: report--489ad88f-0228-5e71-8523-6cfa26bb8caa

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2024-08-14

Date Updated: 2026-04-26

...
...

### Executive summary Aqua Nautilus researchers analyzed a new Gafgyt variant that brute-forces exposed SSH services to execute two in-memory binaries—a Go-compiled scanner/worm and an XMRig cryptominer—targeting both IoT and cloud-native servers (including GPU-equipped hosts). The campaign uses fileless execution from /dev/shm, downloads credential lists from a hard-coded C2 (107.189.5.210), removes logs/history to evade detection, and was observed by Aqua Runtime Protection which generated behavioral alerts and audit logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.