HomeSecurityAndroxgh0st Botnet: Incorporates Mozi payloads to target IoT devices

Androxgh0st Botnet: Incorporates Mozi payloads to target IoT devices

Security researchers have observed some developments in the activity of the Androxgh0st botnet, which include, among other things, the incorporation of payloads from the Mozi botnet.

Androxgh0st Botnet Mozi IoT

CloudSEK 's Threat Research team reports that Androxgh0st, active since January 2024, has begun targeting web servers, using vulnerabilities to infiltrate systems . The botnet is also deploying Mozi payloads , which target Internet of Things (IoT) devices . The integration of elements of the Mozi botnet raises concerns about a possible alliance between the two botnets.

See also: Chinese hackers use Quad7 botnet to steal credentials

Use of vulnerabilities

According to CloudSEK research, the Androxgh0st botnet exploits several vulnerabilities in technologies such as Cisco ASA, Atlassian JIRA, and multiple PHP frameworks. The vulnerabilities provide unauthorized access and facilitate remote code execution on compromised systems.

Some of the vulnerabilities used by the Androxgh0st botnet are:

New analysis by CloudSEK has revealed that the Androxgh0st botnet is now targeting IoT devices, with Mozi payloads, which previously targeted routers and DVRs across China, India, and Albania, before its creators were arrested in 2021.

See also: Mirai-inspired Gorilla Botnet hits 0.3 million targets in 100 countries

Despite the Mozi outage, recent Androxgh0st command and control logs suggest that its payloads have been integrated into Androxgh0st's infrastructure, creating a more widespread infection network and increasing the threat to IoT environments.

Androxgh0st Botnet: Incorporates Mozi payloads to target IoT devices

Protection against botnet

To protect yourself from Botnets, it is important to keep software and operating system up to date. Botnet attacks often exploit known vulnerabilities.

Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

See also: US says Chinese Botnet compromises 260,000 SOHO devices

Using strong passwords and changing them regularly is another way to protect yourself from Botnets (e.g. Androxgh0st). Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect accounts .

Finally, information security training can be particularly useful. Understanding how botnet attacks work and the techniques they use can help you identify and avoid attacks.

Source: www.infosecurity-magazine.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS