The Muhstik botnet was observed actively exploiting the critical Drupal remote code execution flaw CVE-2018-7600 (also known as Drupalgeddon 2) across Drupal 6, 7, and 8 sites, using vulnerable URLs to inject commands and take control of exposed servers. Researchers said exploitation accelerated soon after Drupal released patches, with large-scale scanning beginning in mid-April and multiple threat groups targeting the bug; one cluster tied to Muhstik showed worm-like propagation behavior and put more than a million potentially exposed sites at risk.
Netlab 360 linked the activity to a long-running Tsunami variant that used multi-architecture payloads, IRC-based command-and-control on port 9090, and hard-coded infrastructure and channels prefixed with muhstik. Once installed, the malware deployed miners including XMRig and CGMiner, launched DDoS attacks, stole SSH credentials, attempted SSH brute-force propagation, and used a scanning module to probe Drupal and at least six other internet-facing vulnerabilities or misconfigurations while reporting successful compromises back to attacker-controlled servers.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
360Netlab intercepted multiple Muhstik DDoS attack instructions targeting IP address 46.243.189.102. The commands showed the botnet being used operationally for denial-of-service activity in addition to mining and propagation.
360Netlab observed a Muhstik command-and-control server issuing commands to deliver the aiox86 scanning module. The module was used to exploit Drupal and additional web-facing vulnerabilities across multiple ports.
360Netlab observed a large number of internet scans targeting CVE-2018-7600. The activity marked the beginning of broad exploitation attempts against vulnerable Drupal servers.
MITRE's CVE bulletin warned that CVE-2018-7600 could lead to complete compromise of a Drupal site. This underscored the severity of the vulnerability shortly after disclosure.
Drupal released a patch for the critical remote code execution vulnerability CVE-2018-7600, which affected Drupal 6, 7, and 8. The flaw could allow attackers to take full control of vulnerable sites.
360Netlab attributed one major exploitation campaign against CVE-2018-7600 to a botnet it named Muhstik, a Tsunami variant with worm-like propagation. The researchers said at least three malware groups were exploiting the Drupal flaw.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 62 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.