Gayfemboy is a Mirai-derived Linux botnet active since February 2024 that compromises internet-exposed routers, industrial routers, DVRs, smart-home devices, and other embedded network equipment. It spreads through exploitation of numerous known vulnerabilities, including CVE-2024-12856 in Four-Faith industrial routers, as well as weak Telnet credentials; campaigns observed in 2025 also targeted vulnerable DrayTek, TP-Link, Raisecom, and Cisco products. The botnet supports device scanning, self-updating, remote-command backdoor access, and multiple distributed denial-of-service attack methods, including UDP, TCP, TCP SYN, ICMP, and application-layer floods. It incorporates modified UPX packing, time-based sandbox evasion, process hiding, process termination, randomized or architecture-specific artifact naming, and watchdog-based self-relaunch behavior. A killer component removes competing malware from compromised devices. Infections and DDoS activity have been observed internationally, affecting multiple sectors including manufacturing, technology, construction, media, and communications. No specific threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The advisory lists CVE-2023-1389 as TP-Link Archer AX21 luci.stok command injection among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2024-45885 as a DrayTek mainfunction.cgi command-injection flaw among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2024-45890 as a DrayTek mainfunction.cgi command-injection flaw among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2024-7120 as Raisecom Gateway Devices Base Config command injection among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2024-45887 as a DrayTek mainfunction.cgi command-injection flaw among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The Gayfemboy Mirai-derived botnet campaign exploits a mix of N-day and 0-day vulnerabilities; Annex A lists CVE-2020-14993 as a DrayTek mainfunction.cgi command-injection flaw. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2025-20281 as Cisco ISE InternalUser remote code execution among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2024-48074 as a DrayTek mainfunction.cgi command-injection flaw among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2024-45888 as a DrayTek mainfunction.cgi command-injection flaw among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2024-45884 as a DrayTek mainfunction.cgi command-injection flaw among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The advisory lists CVE-2024-45891 as a DrayTek mainfunction.cgi command-injection flaw among the CVEs affected by the Gayfemboy campaign. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
The Gayfemboy Mirai-derived botnet campaign exploits a mix of N-day and 0-day vulnerabilities; Annex A lists CVE-2020-8515 as a DrayTek mainfunction.cgi command-injection flaw. | FortiGuard Labs observed a resurgence of a Mirai-derived IoT botnet family dubbed “Gayfemboy” in July 2025, which has been exploiting network routers and devices vulnerabilities from vendors such as DrayTek, TP-Link, Raisecom, and Cisco.
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
The offensively named “gayfemboy” botnet was first discovered by Chinese research outfit Qi'anxin XLab back in February 2024.
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
"However, today’s focus, Gayfemboy, is an exception. The Gayfemboy botnet was first discovered by XLab in early February 2024 and has remained active ever since."
12 distinct techniques documented for this family, organized by ATT&CK tactic.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gayfemboy is a sophisticated Linux-based botnet malware that exploits multiple vulnerabilities in network devices to gain remote control. It features advanced evasion techniques, process killing to remove competitors, persistence, sandbox evasion, watchdog functionality, DDoS attack capabilities, and a backdoor. It communicates with C2 servers using public DNS resolvers and supports dynamic C2 infrastructure. The malware is modular, supporting multiple architectures, and is designed for stealth and resilience.
A Mirai-based botnet variant, dubbed 'gayfemboy', that exploits multiple vulnerabilities (including a zero-day in Four-Faith industrial routers) to infect devices and conduct large-scale DDoS attacks. It maintains a large, globally distributed botnet and uses Mirai command formats to scan, update, and attack targets.
Mirai-based botnet variant observed exploiting router/IoT vulnerabilities (including a zero-day in Four-Faith industrial routers, CVE-2024-12856, plus unassigned issues in Neterbit routers and Vimar smart home devices) and weak Telnet credentials to spread, then conducting intermittent DDoS attacks.
A Mirai-derived IoT botnet used primarily for DDoS, with iterative development including modified UPX packing, altered registration packets, process-hiding via mounting a writable directory to /proc/<pid>, active scanning, self-update, and exploitation of multiple vulnerabilities (including a Four-Faith industrial router 0-day) plus Telnet weak credentials to expand infections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.