FBot is a Python-based cloud and web attack tool used to hijack accounts across cloud, SaaS, payment, and messaging platforms. It targets Amazon Web Services, Office365, PayPal, Sendgrid, Twilio, and exposed web application configuration files, with a primary focus on harvesting credentials, validating stolen accounts, and enabling follow-on abuse such as spam operations. The tool has also been observed in a Windows-compiled form. FBot is distinct from cloud attack toolsets built on the common Androxgh0st-derived credential-scraping codebase, although it shares functional similarities with other cloud-focused crimeware such as Legion and may have influenced later tooling in that ecosystem. Across identified samples, the string iDevXploit appears consistently and is credited as the author in the main class, suggesting a stable developer identity or branding. Its AWS-focused functionality includes generation of AWS-style access key material, checking Simple Email Service quotas and sending limits, creating a new privileged IAM user, and enumerating EC2 quotas across regions. These features indicate an emphasis on account takeover, persistence within compromised cloud tenants, and monetization through abuse of cloud email infrastructure. Beyond AWS, FBot includes validation and checking modules for PayPal, Sendgrid, and Twilio accounts, allowing operators to assess the usefulness of stolen credentials and service access. FBot also contains scanning and reconnaissance capabilities. It includes a hidden-configuration scanner that probes common exposed configuration and backup locations to recover secrets, and a CMS scanner that identifies web technologies such as Laravel, Drupal, Magento, WordPress, Joomla, Zimbra, Moodle, OpenCart, phpBB, and MediaWiki. Extracted data can include credentials and configuration values associated with cloud providers, SaaS platforms, databases, and SMTP services. Additional utility functions include IP generation, port scanning, and email validation. Observed activity and code features indicate that FBot is primarily a financially motivated criminal tool centered on credential theft, account hijacking, reconnaissance, and persistence in compromised cloud environments. Samples were observed from 2022 through early 2024, with limited visible evolution and no clear public distribution channel, consistent with private development or selective distribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Private or limited-distribution cloud/SaaS attack tool used to hijack cloud, SaaS, and web service accounts, harvest credentials, abuse AWS SES for spamming, validate PayPal accounts, inspect Twilio accounts, and scrape exposed configuration files for secrets.
Cloud attack tool/family that validates PayPal accounts via requests to an external website; the same validator is also used by other cloud attack tools including Legion Stealer.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.