Gayfemboy: A Botnet Deliver Through a Four-Faith Industrial Router 0-day Exploit.
Essential information
- Published
- 08/01/2025 09:45
- Modified
- 08/01/2025 10:14
- Tags
- 0-day 2025-01-08 CVE-2024-12856 botnet ddos four-faith gayfemboy industrial-router
- Related entities
- 4 vulnerabilities (cve), 56 observables, 1 intrusion sets (apt), 14 techniques (mitre), 2 malware, 7 others
Description
The Gayfemboy botnet, discovered in February 2024, has evolved from a simple Mirai derivative into a sophisticated large-scale botnet. It exploits a 0-day vulnerability in Four-Faith industrial routers and unknown vulnerabilities in other devices to spread. With over 15,000 daily active nodes across 40 grouping categories, it targets multiple countries and industries. The botnet's capabilities include self-updating, scanning, and various DDoS attack methods. It has shown aggressive behavior, retaliating against attempts to analyze it. The botnet's evolution demonstrates the persistent threat of DDoS attacks and the need for comprehensive defense strategies.