FBI Warns of Androxgh0st Malware Botnet Stealing Cloud Credentials

The FBI and CISA have issued a warning about the Androxgh0st malware, which is being used to build a botnet focused on stealing cloud credentials, particularly from AWS and Microsoft. The malware targets vulnerabilities in popular web frameworks and servers, such as Laravel, Apache HTTP Server, and PHPUnit, to steal sensitive information. Threat actors are using the stolen credentials to conduct spam campaigns and deploy additional malicious tools. Network defenders are advised to implement mitigation measures to limit the impact of Androxgh0st malware attacks. CISA has added the CVE-2018-15133 Laravel vulnerability to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to secure their systems against these attacks.
- FBI: Androxgh0st malware botnet steals AWS, Microsoft credentials BleepingComputer
- FBI: Beware of cloud-credential thieves building botnets The Register
- Androxgh0st malware hackers creating large botnet, CISA and FBI warn The Record from Recorded Future News
Reading Insights
0
10
2 min
vs 3 min read
81%
555 → 108 words
Want the full story? Read the original article
Read on BleepingComputer