Skip to content
Malware family IotLinuxNetwork Device

Gafgyt

Gafgyt, also widely known as BASHLITE, is a long-running Linux and IoT botnet malware family primarily used to conscript internet-exposed devices into distributed denial-of-service operations.

Profile source: Mallory opens in a new tab

Gafgyt

Family profile

Gafgyt, also widely known as BASHLITE, is a long-running Linux and IoT botnet malware family primarily used to conscript internet-exposed devices into distributed denial-of-service operations. It has historically targeted routers, cameras, DVRs, embedded Linux systems, and other poorly secured network-connected appliances, and has appeared under multiple related names in reporting, including Bashlite. The family has remained active through numerous forks and customized variants, including campaigns that target both consumer IoT and older enterprise-facing infrastructure.

Gafgyt commonly gains initial access by exploiting known vulnerabilities in exposed devices and services, and by abusing weak or default credentials on remote administration interfaces such as Telnet and SSH. Reported variants have targeted a wide range of flaws in routers, DVRs, DD-WRT firmware, SonicWall Global Management System, TP-Link Archer routers, Langflow deployments, and other internet-facing systems. Some variants use separate scanning or propagation components to identify vulnerable hosts, brute-force credentials, exploit HTTP-exposed services, or abuse exposed Android Debug Bridge interfaces, then deliver architecture-specific Linux payloads.

Once installed, Gafgyt variants typically connect to command-and-control infrastructure and await instructions to launch denial-of-service attacks. Observed capabilities include multiple flood techniques across UDP, TCP, SYN, ICMP, amplification, and HTTP-layer methods. Certain variants also implement persistence through hidden copies, cron jobs, shell profile modification, and self-relaunch behavior, while some aggressively kill competing malware and remove rival persistence artifacts to monopolize infected hosts. Defense-evasion measures such as encrypted or obfuscated command-and-control traffic have also been documented in newer customized builds.

The malware family is strongly associated with botnet activity across Linux-based embedded and IoT environments and has repeatedly been linked to large-scale DDoS campaigns. It has also served as a codebase for derivative botnets and variants used by multiple threat actors, including operations tied to broader IoT botnet ecosystems. Over time, Gafgyt-derived activity has reflected a shift from opportunistic compromise of consumer devices toward exploitation of unpatched enterprise and development infrastructure when such systems expose remotely reachable flaws.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Initial Access
  • Persistence
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 18, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
3 IP / 0 hostnames

Leading locations

  • KH1
  • NL1
  • US1

Leading providers

  • BANATSYNC SRL1
  • ISP/IXP IN CAMBODIA WITH THE BEST VERVICE IN THERE.1
  • Tech Tide Portugal Unipessoal LDA1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to Gafgyt

17 CVEs

MITRE ATT&CK

Gafgyt in ATT&CK

33 distinct techniques

Reporting

Research mentioning Gafgyt

Jul 15
Palo Alto Networks Unit 42

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

The source code contains an IP address of 185.10.68[.]127, which we pivoted on to link TuxBot to Keksec/Kaitori (a Tsunami/Mirai/Gafgyt variant) ecosystems to a shared infrastructure.

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Gafgyt3

Jun 25
Handlers Diary Full

What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary]

TerraBot is an aggressive IoT botnet variant derived from Mirai and Gafgyt source code frameworks...

Jun 10
Security Online Info

COXMO Botnet Variant: Gafgyt Malware Analysis

According to a recent Gafgyt malware analysis, the threat actors achieve initial access by targeting older software vulnerabilities.

Jun 8
Security Affairs

IoT Botnet C0XMO Adds Competitor-Killing Capability

C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks.

Jun 5
Cyber Security News

New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation

A newly discovered variant of the Gafgyt botnet malware, named C0XMO, has been quietly spreading across Linux-based devices by targeting a known vulnerability in DD-WRT router firmware.

Jun 4
Gurucul Threat Research

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO | Community Portal | Gurucul

In March, Labs identified a new Gafgyt botnet variant called C0XMO that spreads by exploiting CVE-2021-27137.

Jun 3
Fortinet Threat Research

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO | FortiGuard Labs

This past March, FortiGuard Labs discovered a new Gafgyt botnet variant, C0XMO, that spreads by exploiting CVE-2021-27137.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.