#gafgyt — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #gafgyt, aggregated by home.social.
-
C0XMO Botnet Exploits DD-WRT Flaw to Spread, Disrupts Rival Malware
Meet C0XMO, a highly sophisticated botnet malware that's disrupting the status quo with its advanced architecture and modular design, allowing it to spread rapidly by exploiting flaws like the DD-WRT vulnerability CVE-2021-27137. Its operators can easily update and adapt the malware to launch devastating DDoS attacks.
-
MalwareBazaar will now parse shell scripts automatically and will try to identify any payload URLs present in it 📄🔍👁️ This will make your life easier when hunting for Linux/Unix malware such as #Mirai and #Gafgyt 💪
Here's an example:
👉 https://bazaar.abuse.ch/sample/ec46f105b049d6674acbf45639883623f2f1cb3eed50eedb4b0e25a27a7b67e2/ -
MalwareBazaar will now parse shell scripts automatically and will try to identify any payload URLs present in it 📄🔍👁️ This will make your life easier when hunting for Linux/Unix malware such as #Mirai and #Gafgyt 💪
Here's an example:
👉 https://bazaar.abuse.ch/sample/ec46f105b049d6674acbf45639883623f2f1cb3eed50eedb4b0e25a27a7b67e2/ -
MalwareBazaar will now parse shell scripts automatically and will try to identify any payload URLs present in it 📄🔍👁️ This will make your life easier when hunting for Linux/Unix malware such as #Mirai and #Gafgyt 💪
Here's an example:
👉 https://bazaar.abuse.ch/sample/ec46f105b049d6674acbf45639883623f2f1cb3eed50eedb4b0e25a27a7b67e2/ -
MalwareBazaar will now parse shell scripts automatically and will try to identify any payload URLs present in it 📄🔍👁️ This will make your life easier when hunting for Linux/Unix malware such as #Mirai and #Gafgyt 💪
Here's an example:
👉 https://bazaar.abuse.ch/sample/ec46f105b049d6674acbf45639883623f2f1cb3eed50eedb4b0e25a27a7b67e2/ -
Gafgyt Malware Broadens Its Scope in Recent Attacks
#Gafgyt
https://www.trendmicro.com/en_us/research/24/l/gafgyt-malware-targeting-docker-remote-api-servers.html -
Gafgyt Malware Broadens Its Scope in Recent Attacks
#Gafgyt
https://www.trendmicro.com/en_us/research/24/l/gafgyt-malware-targeting-docker-remote-api-servers.html -
Fortinet warns that multiple botnets continue exploiting CVE-2023-1389 (8.8 high, disclosed 15 March 2023, added to CISA's KEV Catalog 01 May 2023) TP-Link command injection for wide-scale spread. Botnets include Moobot, Miroi, the Golang-based agent “AGoent,” and the Gafgyt Variant. The blog post explores their infection traffic patterns and offer insights into these botnets. 🔗 https://www.fortinet.com/blog/threat-research/botnets-continue-exploiting-cve-2023-1389-for-wide-scale-spread
#CVE_2023_1389 #TPLink #eitw #activeexploitation #botnet #moobot #miroi #agoent #mirai #gafgyt #threatintel #IOC
-
Fortinet warns that multiple botnets continue exploiting CVE-2023-1389 (8.8 high, disclosed 15 March 2023, added to CISA's KEV Catalog 01 May 2023) TP-Link command injection for wide-scale spread. Botnets include Moobot, Miroi, the Golang-based agent “AGoent,” and the Gafgyt Variant. The blog post explores their infection traffic patterns and offer insights into these botnets. 🔗 https://www.fortinet.com/blog/threat-research/botnets-continue-exploiting-cve-2023-1389-for-wide-scale-spread
#CVE_2023_1389 #TPLink #eitw #activeexploitation #botnet #moobot #miroi #agoent #mirai #gafgyt #threatintel #IOC
-
Fortinet warns that multiple botnets continue exploiting CVE-2023-1389 (8.8 high, disclosed 15 March 2023, added to CISA's KEV Catalog 01 May 2023) TP-Link command injection for wide-scale spread. Botnets include Moobot, Miroi, the Golang-based agent “AGoent,” and the Gafgyt Variant. The blog post explores their infection traffic patterns and offer insights into these botnets. 🔗 https://www.fortinet.com/blog/threat-research/botnets-continue-exploiting-cve-2023-1389-for-wide-scale-spread
#CVE_2023_1389 #TPLink #eitw #activeexploitation #botnet #moobot #miroi #agoent #mirai #gafgyt #threatintel #IOC
-
Fortinet warns that multiple botnets continue exploiting CVE-2023-1389 (8.8 high, disclosed 15 March 2023, added to CISA's KEV Catalog 01 May 2023) TP-Link command injection for wide-scale spread. Botnets include Moobot, Miroi, the Golang-based agent “AGoent,” and the Gafgyt Variant. The blog post explores their infection traffic patterns and offer insights into these botnets. 🔗 https://www.fortinet.com/blog/threat-research/botnets-continue-exploiting-cve-2023-1389-for-wide-scale-spread
#CVE_2023_1389 #TPLink #eitw #activeexploitation #botnet #moobot #miroi #agoent #mirai #gafgyt #threatintel #IOC
-
Our Malware study for the calendar year 2022 is out!
Headline: Interisle reports that malware hosting activity in 2022 was most intense in China, India and United States
Information stealing and ransomware continue to rise, as does misuse of cloud and file sharing services for malware distribution. Also...
• Endpoint malware activity increased 50% over 2021. The Quackbot banking trojan was the most reported endpoint malware.
• IoT malware activity decreased in 2022. Mozi IoT malware reporting sharply declined in early 2022 but showed signs of renewed activity in 4Q 2022.
• 60% of reports identified malware that attacks or probes legitimate web sites. Nearly two-thirds of the reported probes were vulnerability scanners. PHP forum spammers accounted for one-third of attackware reported.
• The use of domain names in malware URLs grew sharply. Interisle found a 121% increase in the use of domain names in 4Q 2022.
• Attackers continued to exploit file sharing services and code repositories to distribute malware.
-
Our Malware study for the calendar year 2022 is out!
Headline: Interisle reports that malware hosting activity in 2022 was most intense in China, India and United States
Information stealing and ransomware continue to rise, as does misuse of cloud and file sharing services for malware distribution. Also...
• Endpoint malware activity increased 50% over 2021. The Quackbot banking trojan was the most reported endpoint malware.
• IoT malware activity decreased in 2022. Mozi IoT malware reporting sharply declined in early 2022 but showed signs of renewed activity in 4Q 2022.
• 60% of reports identified malware that attacks or probes legitimate web sites. Nearly two-thirds of the reported probes were vulnerability scanners. PHP forum spammers accounted for one-third of attackware reported.
• The use of domain names in malware URLs grew sharply. Interisle found a 121% increase in the use of domain names in 4Q 2022.
• Attackers continued to exploit file sharing services and code repositories to distribute malware.
-
Our Malware study for the calendar year 2022 is out!
Headline: Interisle reports that malware hosting activity in 2022 was most intense in China, India and United States
Information stealing and ransomware continue to rise, as does misuse of cloud and file sharing services for malware distribution. Also...
• Endpoint malware activity increased 50% over 2021. The Quackbot banking trojan was the most reported endpoint malware.
• IoT malware activity decreased in 2022. Mozi IoT malware reporting sharply declined in early 2022 but showed signs of renewed activity in 4Q 2022.
• 60% of reports identified malware that attacks or probes legitimate web sites. Nearly two-thirds of the reported probes were vulnerability scanners. PHP forum spammers accounted for one-third of attackware reported.
• The use of domain names in malware URLs grew sharply. Interisle found a 121% increase in the use of domain names in 4Q 2022.
• Attackers continued to exploit file sharing services and code repositories to distribute malware.
-
Our Malware study for the calendar year 2022 is out!
Headline: Interisle reports that malware hosting activity in 2022 was most intense in China, India and United States
Information stealing and ransomware continue to rise, as does misuse of cloud and file sharing services for malware distribution. Also...
• Endpoint malware activity increased 50% over 2021. The Quackbot banking trojan was the most reported endpoint malware.
• IoT malware activity decreased in 2022. Mozi IoT malware reporting sharply declined in early 2022 but showed signs of renewed activity in 4Q 2022.
• 60% of reports identified malware that attacks or probes legitimate web sites. Nearly two-thirds of the reported probes were vulnerability scanners. PHP forum spammers accounted for one-third of attackware reported.
• The use of domain names in malware URLs grew sharply. Interisle found a 121% increase in the use of domain names in 4Q 2022.
• Attackers continued to exploit file sharing services and code repositories to distribute malware.
-
📬 Botnetze übernehmen Millionen von Routern – auch Deinen!
#Cyberangriff #Hacking #AsusRouter #Belkin #Botnetze #DLinkRouter #Fodcha #Gafgyt #IoT #mirai #Mozi #Netgear #RealtekJungleSDK #RedGoBot #Sicherheitsupdates #Unit42 #Zyxel https://tarnkappe.info/artikel/cyberangriff/botnetze-uebernehmen-millionen-von-routern-auch-deinen-264186.html -
📬 Botnetze übernehmen Millionen von Routern – auch Deinen!
#Cyberangriff #Hacking #AsusRouter #Belkin #Botnetze #DLinkRouter #Fodcha #Gafgyt #IoT #mirai #Mozi #Netgear #RealtekJungleSDK #RedGoBot #Sicherheitsupdates #Unit42 #Zyxel https://tarnkappe.info/artikel/cyberangriff/botnetze-uebernehmen-millionen-von-routern-auch-deinen-264186.html -
📬 Botnetze übernehmen Millionen von Routern – auch Deinen!
#Cyberangriff #Hacking #AsusRouter #Belkin #Botnetze #DLinkRouter #Fodcha #Gafgyt #IoT #mirai #Mozi #Netgear #RealtekJungleSDK #RedGoBot #Sicherheitsupdates #Unit42 #Zyxel https://tarnkappe.info/artikel/cyberangriff/botnetze-uebernehmen-millionen-von-routern-auch-deinen-264186.html -
📬 Botnetze übernehmen Millionen von Routern – auch Deinen!
#Cyberangriff #Hacking #AsusRouter #Belkin #Botnetze #DLinkRouter #Fodcha #Gafgyt #IoT #mirai #Mozi #Netgear #RealtekJungleSDK #RedGoBot #Sicherheitsupdates #Unit42 #Zyxel https://tarnkappe.info/artikel/cyberangriff/botnetze-uebernehmen-millionen-von-routern-auch-deinen-264186.html