AndroxGh0st Malware Integrates Mozi Botnet to Target IoT and Cloud Services
Essential information
- Published
- 08/11/2024 18:33
- Modified
- 08/11/2024 19:22
- Tags
- 2024-11-08 CVE-2014-2120 CVE-2018-10561 CVE-2018-10562 CVE-2021-26086 CVE-2021-41277 CVE-2022-1040 CVE-2022-21587 CVE-2023-1389 CVE-2024-36401 CVE-2024-4577 androxgh0st botnet cloud services credential stealing iot laravel mozi remote code execution wordpress
- Related entities
- 1 observables, 1 intrusion sets (apt), 8 techniques (mitre), 2 malware
Description
The AndroxGh0st malware has expanded its capabilities by incorporating the Mozi botnet to target IoT devices and cloud services. This Python-based tool, known for attacking Laravel applications, now exploits a wider range of vulnerabilities in internet-facing applications. The malware uses remote code execution and credential-stealing methods to maintain persistent access, leveraging unpatched vulnerabilities to infiltrate critical infrastructures. AndroxGh0st's integration with Mozi suggests a possible operational alliance, allowing it to propagate to more devices. The botnet cycles through common administrative usernames and targets WordPress backends. This collaboration enhances the effectiveness and efficiency of their combined botnet operations, potentially indicating control by the same cybercriminal group.