The US Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have warned that cybercriminals behind the AndroxGh0st malware are creating a botnet to “identify and exploit victims on target networks.”

AndroxGh0st is a Python-based malware discovered by Lacework in December 2022.
The tool can infiltrate servers that are vulnerable to known vulnerabilities. The goal is to access Laravel environment files and steal credentials for applications such as Amazon Web Services (AWS), Microsoft Office 365, SendGrid, and Twilio.
See also: Increased botnet activity in the last month
Some of the vulnerabilities exploited by the botnet malware are CVE-2017-9841 (PHPUnit), CVE-2021-41773 (Apache HTTP Server) and CVE-2018-15133 (Laravel Framework).
“AndroxGh0st has multiple capabilities to enable SMTP abuse, including scanning, exploiting exposed credentials and APIs, and even deploying web shells,” Lacework said. “For AWS specifically, the malware scans and analyzes AWS keys, but also has the ability to generate keys for brute-force attacks.”
According to researchers, AndroxGh0st's capabilities make it a powerful threat. Cybercriminals use it to download additional malicious payloads and maintain permanent access to compromised systems.
Recently, SentinelOne uncovered a similar malicious tool called FBot, which is also used to compromise web servers, cloud services, content management systems (CMS), and SaaS platforms.
See also: NoaBot: New botnet targets SSH Servers for crypto mining

Protection from the AndroxGh0st malware botnet
To protect yourself from the AndroxGh0st Botnet, it is important to keep your device's software and operating system up to date. attacks exploit known vulnerabilities that have been fixed in more recent versions of the software (as is the case in this case).
Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.
Using strong passwords and changing them regularly is another way to protect yourself from the AndroxGh0st Botnet. Botnet attacks often try to guess passwords ,so using strong passwords and changing them regularly can help protect your accounts.
See also: QNAP VioStor NVR: Vulnerability actively exploited by botnet
Finally, security training can be particularly useful. Understanding how botnet attacks work and the techniques they use can help you identify and avoid attacks.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, CISA and the FBI recommend:
- Make sure the default configuration for all URIs is to deny all requests unless there is a specific need for them to be accessible.
- Make sure any live Laravel applications are not in “debug” or testing mode. Remove all cloud credentials from .env files and revoke them.
- Scan the server's file system for unrecognized files , particularly in the /vendor/phpunit/phpunit/src/Util/PHP directory or folder.
- Check outgoing GET requests (via the cURL command) for file hosting sites such as GitHub, pastebin, etc., especially when the request accesses a .php file.
Source: thehackernews.com
