AndroxGh0st Malware Targets Laravel Apps to Steal Cloud Credentials
ID: 8c550a33-7514-5865-b303-1d4da03ad859
STIX ID: report--8c550a33-7514-5865-b303-1d4da03ad859
Feed Name: The Hacker News
Threat Score
Juniper Threat Labs and other vendors have reported on AndroxGh0st, a Python-based SMTP cracker and infostealer active since at least 2022 that exploits known vulnerabilities in Apache, Laravel, and PHPUnit to access .env files and harvest cloud credentials (AWS, Twilio, SendGrid), enabling botnet formation and deployment of additional payloads such as miners and reverse proxies; organizations are advised to patch affected components and monitor cloud environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
