SentinelOne reported that FBot, a Python-based cloud and web attack tool, is being used to harvest credentials and hijack accounts across AWS, Office 365, PayPal, SendGrid, Twilio, and exposed web application configuration files. The malware scans Laravel, PHP, and AWS-related paths for leaked secrets, validates stolen or discovered accounts, and includes functions to generate AWS-style access key formats and SendGrid-style API keys. Researchers said FBot shares operational similarities with cloud-focused malware such as AlienFox, GreenBot, Predator, and Legion, but does not appear to reuse the common Androxgh0st codebase.
The tool shows a strong emphasis on AWS abuse for follow-on operations, including checking SES sending quotas, creating a privileged IAM user, and enumerating EC2 quotas across regions, behavior consistent with account takeover and spam enablement. SentinelOne observed FBot samples dating from July 2022 through January 2024, with limited evolution and no clear public distribution channel, suggesting it may be privately developed or selectively shared. The report urged defenders to enforce MFA for AWS programmatic access and monitor for newly created AWS users and significant SaaS mail configuration changes as indicators of compromise or abuse.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-07, SentinelOne published a report detailing FBot's capabilities, including AWS account takeover functions, SaaS account validation, and scanning for exposed secrets in web applications. The report recommended MFA for AWS programmatic access and monitoring for new AWS users and major SaaS mailing configuration changes.
SentinelOne said it observed FBot samples through January 2024 and noted limited evolution over that period. The report also assessed that FBot did not appear to reuse the common Androxgh0st codebase, despite functional similarities to related cloud-focused malware families.
SentinelOne reported observing FBot, a Python-based malware and attack tool targeting cloud and payment services, in samples dating from July 2022. The tooling targeted services including AWS, Office365, PayPal, Sendgrid, Twilio, and exposed web application configuration files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.