AndroxGh0st is a Python-based cloud and web-application attack tool and botnet used to discover and compromise internet-exposed Laravel and other vulnerable web applications. It systematically scans for exposed environment-configuration files and extracts credentials, API keys, and Laravel application keys, with particular focus on AWS, Microsoft 365, SendGrid, Twilio, and SMTP-related services. Stolen cloud credentials can be abused to enumerate cloud environments, create IAM users and policies, and support further scanning or email-service abuse.
The malware has been observed exploiting known vulnerabilities including CVE-2017-9841 in PHPUnit, CVE-2018-15133 in Laravel, and CVE-2021-41773 in Apache HTTP Server. It can use successful exploitation to deploy web shells, download additional payloads, and maintain access to compromised web servers. AndroxGh0st activity is associated with automated reconnaissance and broad opportunistic targeting rather than a reliably attributable threat actor.
Later activity has been reported to incorporate IoT-focused payloads associated with the Mozi botnet, expanding targeting beyond web applications to vulnerable network-connected devices. This reported overlap indicates use of botnet functionality for victim identification, exploitation, and follow-on compromise, but does not establish a confirmed common operator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
threat actors deploying Androxgh0st have been observed exploiting CVE-2017-9841 to remotely run hypertext preprocessor (PHP) code on fallible websites via PHPUnit. | Androxgh0st malware has been observed establishing a botnet for victim identification and exploitation in target networks. According to open source reporting, Androxgh0st is a Python-scripted malware primarily used to target .env files that contain confidential information, such as credentials for various high profile applications.
The vulnerability defined in CVE-2018-15133 indicates that on Laravel applications, XSRF token values are subject to an un-serialized call, which can allow for remote code execution. | Androxgh0st malware has been observed establishing a botnet for victim identification and exploitation in target networks. According to open source reporting, Androxgh0st is a Python-scripted malware primarily used to target .env files that contain confidential information, such as credentials for various high profile applications.
In correlation with CVE-2021-41773, Androxgh0st actors have been observed scanning vulnerable web servers running Apache HTTP Server versions 2.4.49 or 2.4.50. | Androxgh0st malware has been observed establishing a botnet for victim identification and exploitation in target networks. According to open source reporting, Androxgh0st is a Python-scripted malware primarily used to target .env files that contain confidential information, such as credentials for various high profile applications.
CloudSEK’s recent investigation reveals that the Androxgh0st botnet has evolved significantly since its early activity in 2023, leveraging a wide range of Initial Access Vectors (IAVs). Misconfigured/vulnerable servers linked to academic institutions and public domains... were found hosting command-and-control (C2)logger panels. The botnet exploits popular platforms (e.g., Apache Shiro, Spring framework, WordPress) and IoT devices (Lantronix), enabling remote code execution, sensitive data theft, and cryptomining.
CloudSEK’s recent investigation reveals that the Androxgh0st botnet has evolved significantly since its early activity in 2023, leveraging a wide range of Initial Access Vectors (IAVs). Misconfigured/vulnerable servers linked to academic institutions and public domains... were found hosting command-and-control (C2)logger panels. The botnet exploits popular platforms (e.g., Apache Shiro, Spring framework, WordPress) and IoT devices (Lantronix), enabling remote code execution, sensitive data theft, and cryptomining.
CloudSEK’s recent investigation reveals that the Androxgh0st botnet has evolved significantly since its early activity in 2023, leveraging a wide range of Initial Access Vectors (IAVs). Misconfigured/vulnerable servers linked to academic institutions and public domains... were found hosting command-and-control (C2)logger panels. The botnet exploits popular platforms (e.g., Apache Shiro, Spring framework, WordPress) and IoT devices (Lantronix), enabling remote code execution, sensitive data theft, and cryptomining.
CloudSEK’s recent investigation reveals that the Androxgh0st botnet has evolved significantly since its early activity in 2023, leveraging a wide range of Initial Access Vectors (IAVs). Misconfigured/vulnerable servers linked to academic institutions and public domains... were found hosting command-and-control (C2)logger panels. The botnet exploits popular platforms (e.g., Apache Shiro, Spring framework, WordPress) and IoT devices (Lantronix), enabling remote code execution, sensitive data theft, and cryptomining.
CloudSEK’s recent investigation reveals that the Androxgh0st botnet has evolved significantly since its early activity in 2023, leveraging a wide range of Initial Access Vectors (IAVs). Misconfigured/vulnerable servers linked to academic institutions and public domains... were found hosting command-and-control (C2)logger panels. The botnet exploits popular platforms (e.g., Apache Shiro, Spring framework, WordPress) and IoT devices (Lantronix), enabling remote code execution, sensitive data theft, and cryptomining.
CloudSEK’s recent investigation reveals that the Androxgh0st botnet has evolved significantly since its early activity in 2023, leveraging a wide range of Initial Access Vectors (IAVs). Misconfigured/vulnerable servers linked to academic institutions and public domains... were found hosting command-and-control (C2)logger panels. The botnet exploits popular platforms (e.g., Apache Shiro, Spring framework, WordPress) and IoT devices (Lantronix), enabling remote code execution, sensitive data theft, and cryptomining.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Androxgh0st malware has been observed establishing a botnet [T1583.005] for victim identification and exploitation in target networks.
Andoxgh0st actors have been observed creating new AWS instances to use for conducting additional scanning activity [T1583.006].
FBot has three functions dedicated to AWS account attacks. The first is an AWS API Key Generator, handled by function aws_generator, which generates a random AWS access key ID by appending 16 randomly selected alphabetic characters to the standard AKIA prefix. Then, it generates a secret key from 40 randomly selected alphabetic characters.
Androxgh0st malware also supports numerous functions capable of abusing the Simple Mail Transfer Protocol (SMTP), such as scanning and exploiting exposed credentials [T1078]...
Androxgh0st aimed to steal sensitive login data from these files... Upon successful credential retrieval, Androxgh0st leverages CVE-2018-15133... as long as they are in possession of the application's APP_KEY
The response is parsed for keys and secrets related to the following services and the result is written to a text file: AWS ... Office365 ... Sendgrid ... Twilio ... Mailgun | FBot is primarily designed for actors to hijack cloud, SaaS, and web services. There is a secondary focus on obtaining accounts to conduct spamming attacks. Actors can use the credential harvesting features to obtain initial access, which they can sell to other parties.
Androxgh0st malware also supports numerous functions capable of abusing the Simple Mail Transfer Protocol (SMTP), such as scanning [T1046]...
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet leveraging CVE-2017-9841 in active exploitation campaigns against exposed PHPUnit installations.
Open-source credential scraping module/tool used by multiple cloud attack tools to parse environment configuration files and extract mail and cloud service credentials.
A cloud threat family hunted via unique recycled strings and variables that recur across many related tools.
Malware that scans for exposed Laravel .env files to steal sensitive credentials, including APP_KEY values, and then leverages them to gain unauthorized access and potentially achieve pre-authenticated remote command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.