Gafgyt is a long-running Linux botnet malware family primarily associated with the compromise of internet-exposed IoT devices and embedded Linux systems. It is widely recognized as one of the dominant families in the Linux IoT threat landscape alongside Mirai, and it has spawned numerous forks and variants over time. Gafgyt is chiefly used to build botnets for distributed denial-of-service operations, including abuse of game-server query protocols for reflection and amplification. The family is commonly discussed as a malware ecosystem rather than a single tightly controlled intrusion set, with multiple operators and derivative strains using similar code and tradecraft. Operationally, Gafgyt is associated with scanning and opportunistic targeting of exposed systems, followed by compromise of weakly secured devices and enrollment into botnets for follow-on attack activity. Its observed behavior is consistent with botnet-oriented campaigns emphasizing network attack capability rather than stealthy espionage. Historical reporting links Gafgyt variants to DDoS amplification activity involving Valve Source Engine and related A2S query mechanisms. Because the name refers to a malware family and botnet lineage used by multiple actors, attribution to a single organization or country is not supported at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a botnet family/operator contextually associated with abuse of Valve Source Engine ports for DDoS amplification.
Mentioned as a related botnet family during classification of the analyzed ELF malware sample.
Mentioned only as background context for the Linux IoT malware landscape.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.