November 9, 2024 – The Androxgh0st botnet has significantly enhanced its exploitation capabilities by adding a variety of new vulnerabilities to its arsenal, some of which appear to be inherited from the now-defunct Mozi botnet, according to a report by cybersecurity firm CloudSEK.
Androxgh0st, which has been active since 2022, is known for stealing cloud credentials and exploiting vulnerabilities in various web frameworks and servers. Recently, it has begun targeting Internet of Things (IoT) devices, including home routers, thereby expanding its reach and potential impact.
Since the joint advisory issued by the FBI and CISA in January regarding Androxgh0st, the botnet operators have integrated additional exploits, now targeting technologies such as Cisco ASA, Atlassian JIRA, Metabase GeoJSON, Oracle EBS, and Sophos Firewall, alongside previously known IoT vulnerabilities.
CloudSEK researchers noted that the botnet’s heightened activity indicates a strategic shift towards exploiting a broader range of web application vulnerabilities to gain initial access. They highlighted the importance of addressing these vulnerabilities, especially since the botnet has reportedly added nine new exploits, allowing it to compromise a wider array of outdated devices.
Among the newly targeted vulnerabilities are several critical issues, including a command injection flaw in TP-Link routers and remote code execution vulnerabilities in various network devices. The report suggests that Androxgh0st may have integrated Mozi’s payloads into its operational framework, thus enhancing its capabilities to infect and propagate through IoT devices.
CloudSEK urges organizations to proactively scan for vulnerable devices and applications within their networks and to apply necessary patches promptly, as the number of Androxgh0st infections continues to escalate.