Flodrix is a DDoS botnet malware family associated with exploitation of vulnerable internet-exposed Langflow AI workflow deployments. It was distributed through exploitation of CVE-2025-3248, a critical missing-authentication vulnerability affecting Langflow versions prior to 1.3.0. Compromised Langflow servers are used to deploy the botnet for distributed denial-of-service activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In June 2025, another critical vulnerability (CVE-2025-3248, CVSS score: 9.8) was abused to distribute the Flodrix botnet malware.
...its lower-scored sibling vulnerability, tracked as CVE-2026-33017 with a CVSS score of 9.3, which has already been exploited thousands of times... CVE-2026-33017 (the RCE): CISA KEV (added March 25, 2026), CVSS 9.3, ~7,000 servers under attack, exploited within ~20 hours of disclosure. It has been used for AWS-key theft, .env/.db harvest, and malicious NATS-worker deployment.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously documented DDoS botnet payload family targeting Langflow; it is included as context and comparison for LF3.
Mentioned as malware distributed in a separate prior Langflow exploitation case.
A botnet referenced as having been spread by threat actors through exploitation of CVE-2025-3248 in Langflow.
Botnet malware delivered by exploiting a Langflow vulnerability; used to conduct DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.