Researchers reported that multiple Gafgyt/Bashlite variants targeting IoT devices are reusing leaked Mirai source code while continuing to evolve their infection and attack capabilities. Analyses found shared modules for HTTP, UDP, and TCP flooding, a telnet brute-force scanner, and other botnet functions, alongside exploitation of known router flaws including CVE-2017-17215, CVE-2014-8361, and CVE-2018-10561. Separate reporting also described campaigns abusing exposed SSH, Telnet, and WeMo UPnP services to drop first-stage shell scripts and architecture-specific ELF payloads that conscript devices into distributed denial-of-service operations.
Recent samples show operators tailoring payloads for stealth and persistence after compromise. One analyzed ELF binary, packed with UPX and masquerading as /usr/bin/apt, was observed beaconing to 45.61.186.4:13561, killing rival malware, flushing iptables, stopping local firewall services, clearing shell history, and altering DNS settings before accepting commands for TCP, UDP, GRE, ICMP, HTTP, and game-server-focused floods. Other reports noted process renaming, heavy forking, changing filenames and infrastructure, and added backdoor or cryptomining functions, indicating that Gafgyt operators are using modular, frequently modified malware to evade detection and sustain IoT-focused DDoS campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
In late September 2022, Nozomi Networks honeypots captured commonly abused default SSH and Telnet credentials such as admin:admin and root:root used in Gafgyt-related intrusion attempts.
On 2021-08-27, investigators found an IoT device accessing a malicious sample from a campaign tagged Korpze1233121337. CUJO AI analyzed the Gafgyt/Mirai-style fork and reported two newly observed DDoS modules, attacks_vector_openvpn_swak and attacks_vector_wabba_jack, along with Telnet-based propagation and C2 infrastructure at 103.161.17.233.
Belkin said the WeMo vulnerability discussed in Trend Micro's analysis had been detected and remediated for all affected devices in 2015.
Trend Micro noted that Bashlite, also known as Gafgyt, was previously known for large-scale distributed denial-of-service attacks in 2014.
SecurityScorecard analyzed a recently compiled, UPX-packed Gafgyt ELF sample that disguised itself as /usr/bin/apt, killed suspected Mirai processes, disabled local defenses, and connected to command-and-control server 45.61.186.4:13561.
Nozomi Networks documented Gafgyt variants ranging from feature-rich to lightweight samples, indicating campaign-specific tailoring or modular malware capabilities. The analysis described brute-force initial access, staged payload delivery, DDoS functions, and evasion features such as process renaming and forking.
Uptycs reported that some Gafgyt variants embedded exploits for CVE-2017-17215, CVE-2014-8361, and CVE-2018-10561 to compromise Huawei, Realtek, and GPON routers and fetch additional payloads.
Uptycs threat researchers detected several Gafgyt variants that reused Mirai botnet modules including HTTP, UDP, TCP, STD, and telnet brute-force functionality. The analysis reinforced Gafgyt's role as an IoT-focused DDoS botnet.
Trend Micro disclosed its findings on the updated Bashlite campaign to Belkin. Belkin responded by urging customers to update their devices and mobile apps to obtain the latest security fixes.
Trend Micro observed detections of updated Bashlite variants on March 21 across Taiwan, the United States, Thailand, Malaysia, Japan, and Canada. The campaign targeted devices exposing the WeMo UPnP API and added mining, backdoor, and bot-killing capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
nozominetworks.com
Open sourcecujo.com
Open sourceuptycs.com
Open sourceblog.trendmicro.com
Open sourcesecurityscorecard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.