Feds Warn of AndroxGh0st Botnet Targeting AWS, Azure, and Office 365 Credentials
ID: 356febda-1773-5d94-9459-21eac7ab757f
STIX ID: report--356febda-1773-5d94-9459-21eac7ab757f
Feed Name: The Hacker News
Threat Score
**AndroxGh0st malware campaign:** CISA and the FBI warn that AndroxGh0st, a Python-based cloud attack tool, is being used in the wild to exploit known vulnerabilities, steal Laravel and cloud credentials (AWS, Office365, SendGrid, Twilio), create malicious AWS users/instances, deploy web shells, and enable SMTP abuse and large-scale scanning; related tools (AlienFox, FBot) and increased botnet scanning activity using cheap cloud accounts were also noted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
