216.73.216.36

AndroxGh0st Malware Integrates Mozi Botnet to Target IoT and Cloud Services

· Published 08/11/2024 18:33 · Modified 08/11/2024 19:22

Export JSON

Essential information

Published
08/11/2024 18:33
Modified
08/11/2024 19:22
Tags
2024-11-08 CVE-2014-2120 CVE-2018-10561 CVE-2018-10562 CVE-2021-26086 CVE-2021-41277 CVE-2022-1040 CVE-2022-21587 CVE-2023-1389 CVE-2024-36401 CVE-2024-4577 androxgh0st botnet cloud services credential stealing iot laravel mozi remote code execution wordpress
Related entities
1 observables, 1 intrusion sets (apt), 8 techniques (mitre), 2 malware

Description

The malware has expanded its capabilities by incorporating the to target devices and . This Python-based tool, known for attacking applications, now exploits a wider range of vulnerabilities in internet-facing applications. The malware uses and credential-stealing methods to maintain persistent access, leveraging unpatched vulnerabilities to infiltrate critical infrastructures. 's integration with suggests a possible operational alliance, allowing it to propagate to more devices. The cycles through common administrative usernames and targets backends. This collaboration enhances the effectiveness and efficiency of their combined operations, potentially indicating control by the same cybercriminal group.

External references