Gafgyt, widely known as Bashlite, is a long-running Linux and IoT botnet malware family primarily used for distributed denial-of-service attacks. First active in 2014, it initially spread through exploitation of Shellshock on vulnerable embedded systems and subsequently proliferated after its source code leaked in 2015. The family has many aliases, including Lizkebab, Qbot, Torlus, PinkSlip, and LizardStresser, and has produced numerous forks and derivatives.
Gafgyt commonly compromises internet-exposed routers, cameras, DVRs, GPON equipment, and other embedded Linux devices through Telnet or SSH weak-password attacks and exploitation of publicly known remote-code-execution vulnerabilities. Variants have targeted vulnerable router and IoT products from multiple vendors, and typically retrieve architecture-specific payloads following compromise. Supported architectures across variants include ARM, MIPS, PowerPC, SuperH, x86, and x64.
Infected devices communicate with command-and-control infrastructure, often using lightweight IRC-like protocols; some variants use Tor-based infrastructure to conceal command-and-control communications. Core functions include network scanning, credential brute forcing, payload retrieval, process termination to remove competing botnets, and DDoS attacks. Common attack modes include TCP, UDP, HTTP, DNS, TLS, GRE, and TCP-flag floods. Some variants also execute shell commands, use string obfuscation, impersonate legitimate process names, and establish persistence through cron jobs or shell-startup modifications. Certain newer Gafgyt-derived activity has extended beyond IoT devices to Linux servers and cloud-oriented environments, including cryptomining campaigns.
Gafgyt has been associated with multiple criminal botnet operations. Historical activity was attributed to Lizard Squad, while later Gafgyt variants and related botnets have been linked to the Keksec cybercrime ecosystem. Its leaked codebase has also materially influenced related botnets, including Hakai, Simps, Enemybot, and other Linux IoT malware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers exploit CVE-2021-27137 in vulnerable DD-WRT routers by sending specially crafted SSDP M-SEARCH requests to UDP port 1900. Successful exploitation results in remote code execution and malware deployment.
OWARI retained the default password technique to propagate the victim device and added a few exploit scanners like CVE-2017–17215 Huawei exploit... Gafgyt primarily targets vulnerable IoT devices... It also frequently exploits known vulnerabilities like CVE-2017-17215 and CVE-2018-10561 to deliver next-stage payloads to infected devices. | The original Mirai was consistently tweaked to compete with its “DDoS-as-a-Service” provider rival vDOS and their Gafgyt botnet.
Gafgyt primarily targets vulnerable IoT devices, particularly Huawei routers, Realtek routers, and ASUS devices. It also frequently exploits known vulnerabilities like CVE-2017-17215 and CVE-2018- 10561 to deliver next-stage payloads to infected devices. | The original Mirai was consistently tweaked to compete with its “DDoS-as-a-Service” provider rival vDOS and their Gafgyt botnet.
In its previous iterations, Bashlite exploited Shellshock to gain a foothold into the vulnerable devices. | We uncovered an updated Bashlite malware designed to add infected internet-of-things devices to a distributed-denial-of-service (DDoS) botnet. Bashlite (also known as Gafgyt, Lizkebab, Qbot, Torlus, and LizardStresser) gained notoriety for its use in large-scale DDoS attacks in 2014...
the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562/10562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device.
CVE-2014-8361 ... Different devices using the Realtek SDK with the miniigd daemon
At that time we found that IP hosting samples of Gafgyt containing an exploit for a recently disclosed SonicWall vulnerability (CVE-2018-9866) affecting older, unsupported versions of SonicWall Global Management System (GMS) (8.1 and older). | The new Gafgyt version targets a newly disclosed vulnerability affecting older, unsupported versions of SonicWall’s Global Management System (GMS).
自从Log4J漏洞被曝光后... 2022年2月9日,360Netlab的蜜罐系统捕获了一个未知的ELF文件通过Log4J漏洞传播... B1txor20...目前通过Log4j漏洞传播 | 期间我们看到了Elknot,Gafgyt,Mirai等老朋友的从不缺席,也见证了一些新朋友的粉墨登场。
On June 2, 2022, Volexity performed a coordinated disclosure of an under-exploit zero day in Atlassian Confluence, CVE-2022-26134. Since the original disclosure and subsequent publication of various proofs of concept, Barracuda researchers have discovered a large number of attempts to exploit this vulnerability. | First, let’s look at one attempt to deliver the Gafgyt DDoS botnet malware... The attacker is essentially attempting to create a botnet member on any system that can be infected.
Attackers exploit a Langflow remote code execution flaw to drop a stripped-down DDoS payload... the code validation endpoint executes untrusted Python “without proper sandboxing.”... CISA added CVE-2025-3248 to its KEV catalog in May 2025, and GreyNoise has tracked hundreds of exploit source IPs. | Akamai found a new Gafgyt botnet campaign that hijacks AI infrastructure. Attackers exploit a Langflow remote code execution flaw to drop a stripped-down DDoS payload.
Indicators of Compromise (IoCs):- Type Indicator Description CVE CVE-2016-15047 Avtech DVR Camera authentication bypass and command execution exploit
Indicators of Compromise (IoCs):- Type Indicator Description CVE CVE-2025-34054 Avtech DVR Camera authentication bypass and command execution exploit
C0XMO’s success depends on known, unpatched vulnerabilities that have had available fixes for some time. CVE-2021-27137 in DD-WRT, CVE-2015-2051 in D-Link devices, CVE-2022-35914 in GLPI project software, and multiple Avtech DVR camera flaws are all part of its exploit toolkit.
C0XMO’s success depends on known, unpatched vulnerabilities that have had available fixes for some time. CVE-2021-27137 in DD-WRT, CVE-2015-2051 in D-Link devices, CVE-2022-35914 in GLPI project software, and multiple Avtech DVR camera flaws are all part of its exploit toolkit.
Tracked as CVE-2023-1389, the flaw is a high-severity unauthenticated command injection problem in the locale API reachable through the TP-Link Archer AX21 web management interface. | Recently, we observed multiple attacks focusing on this year-old vulnerability, spotlighting botnets like Moobot, Miori, the Golang-based agent "AGoent," and the Gafgyt Variant.
CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
Botnet attacks aimed at PHP servers involved the exploitation of PHPUnit, Laravel, and ThinkPHP Framework remote code execution flaws, tracked as CVE-2017-9841, CVE-2021-3129, and CVE-2022-47945, respectively.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gafgyt_tor share the same origin with the Gafgyt samples described by the keksec group, the core function is still DDoS attacks and scanning.
The original Mirai was consistently tweaked to compete with its “DDoS-as-a-Service” provider rival vDOS and their Gafgyt botnet.
Keksec actively maintains three main families, Gafgyt, Tsunami and Necro, with new features constantly being added.
BASHLITE (also known as Gafgyt, Lizkebab, PinkSlip, Qbot, Torlus and LizardStresser) is malware which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS).
27 distinct techniques documented for this family, organized by ATT&CK tactic.
We can see that Keksec launched scans and attacks on targets across the network almost non-stop. Our honeypots see new variants and exploits all the time, with the exception of some occasional breaks. When a new exploit is introduced, the scans increase significantly.
The malware creates cron jobs that execute every 15 minutes... to ensure execution after system reboots.
An attacker can then remotely issue commands ... and download other files to the compromised devices.
Most of the Gafgyt and Tsunami samples we captured were not packed... String encoding... Necro also cryptographically protects the string by first performing character substitution and then doing zip compression.
A very traditional technique on Linux systems is to use random strings to override argv parameters and prctl(PR_SET_NAME,buf) to change the process name and start parameters in order to disguise the process.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
After persistence is established, C0XMO connects to its command-and-control infrastructure and performs a custom multi-stage handshake.
We found Tor proxy being used to communicate with the C2 in both Gafgyt and Necro.
In Gafgyt Tor proxy is used to talk to the C2 through a built-in proxy list. Up to 173 proxy IPs can be used for a single sample.
548 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
92 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentionné uniquement comme botnet concurrent dont les processus sont supprimés par Masjesu.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
IoT-focused malware that infects vulnerable devices, adds them to a DDoS botnet, provides backdoor access, includes Telnet scanning and brute-force propagation, can download additional payloads, supports multiple DDoS flood commands, and can fetch cryptocurrency-mining and bricker malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.