Skip to content

Gafgyt

Gafgyt, also widely known as BASHLITE, is a long-running Linux and IoT botnet malware family primarily used to conscript vulnerable devices into distributed denial-of-service operations.

Profile source: Mallory opens in a new tab

Gafgyt

Family profile

Gafgyt, also widely known as BASHLITE, is a long-running Linux and IoT botnet malware family primarily used to conscript vulnerable devices into distributed denial-of-service operations. It has historically targeted embedded Linux systems such as routers, cameras, DVRs, and other internet-exposed appliances, and newer variants have also been observed targeting enterprise-facing Linux infrastructure and AI development servers. The family is notable for extensive code reuse and branching, with many variants and related strains sharing overlapping functionality, exploit modules, and infrastructure patterns.

Gafgyt commonly gains initial access by exploiting known vulnerabilities in exposed devices and services, and some variants also use credential attacks against weakly secured remote administration interfaces. Observed campaigns have targeted router and IoT flaws as well as enterprise software vulnerabilities, including exploitation of Langflow remote code execution to deploy a stripped-down DDoS-focused payload on x86_64 Linux servers, exploitation of older SonicWall GMS vulnerabilities, and exploitation of DD-WRT UPnP flaws by the C0XMO variant. Several variants deliver architecture-specific Linux binaries to maximize infection success across heterogeneous hardware.

Its core purpose is botnet enrollment and remote attack execution. Gafgyt variants typically connect to command-and-control infrastructure and await instructions to launch network flooding attacks. Documented capabilities include multiple DDoS methods such as UDP, TCP, SYN, ICMP, HTTP-layer floods, HOLD-style attacks, and amplification techniques in some variants. Certain branches also include scanning modules, update mechanisms, process killing to remove competing malware, and persistence through cron jobs, shell profile modification, hidden copies, or watchdog-style relaunch behavior. Other observed variants are more minimal and omit persistence, lateral movement, or secondary monetization features in favor of pure flooding capability.

The malware family has been linked over time to a broad ecosystem of criminal botnet activity rather than a single stable operator. Variants and derivative botnets such as C0XMO, TerraBot, and other Gafgyt-based strains have been observed in campaigns targeting unmanaged IoT fleets, small-office and home-office equipment, and occasionally enterprise systems. Gafgyt remains relevant because old source code, modular reuse, and the continued exposure of unpatched Linux-based devices allow operators to rapidly adapt the family to new exploits and targets.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Initial Access
  • Persistence
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 13, 2026
Last activity
Aug 13, 2026
Feed role
C2 / Distribution
Host form
2 IP / 0 hostnames

Leading locations

  • US2

Leading providers

  • Virtual Machine Solutions LLC1
  • VpsQuan L.L.C.1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to Gafgyt

17 CVEs

MITRE ATT&CK

Gafgyt in ATT&CK

34 distinct techniques

Reporting

Research mentioning Gafgyt

Jul 22
Security Online Info

Gafgyt Botnet Hijacks Langflow for DDoS Attacks

Attackers are actively exploiting CVE-2025-3248, a remote code execution flaw in Langflow’s code validation API, to compromise internet-exposed AI development servers and deploy a customized Gafgyt/BASHLITE malware variant on x86_64 Linux systems. Akamai reported that the intrusion chain uses untrusted Python execution to fetch a Linux binary from a staging server, launch it from a temporary directory, and turn the host into a bot focused on distributed denial-of-service activity rather than cryptomining, persistence, or lateral movement. The malware reportedly supports multiple flood modes, including UDP, TCP, HOLD, and junk/STD, and uses a modified RC4-based cipher to obscure command-and-control traffic and hinder standard decoding. CISA added CVE-2025-3248 to its Known Exploited Vulnerabilities catalog, while GreyNoise observed hundreds of exploit source IPs targeting the flaw. Defenders are being urged to patch Langflow, isolate AI development environments, place exposed instances behind a WAF, enforce outbound filtering including blocking unauthorized traffic such as port 1337, and deploy YARA detections keyed to the malware’s distinctive cipher seed bytes.

Jul 21
Security Online Info

TuxBot v3 Evolution: LLM-Built IoT Botnet Exposed

Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnet’s source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malware’s working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.

Jul 16
Scworld

New TuxBot v3 Evolution IoT botnet framework shows signs of AI development | brief | SC Media

Jul 16
Security Affairs

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

Jul 16
Cyber Security News

New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

Jul 16
Cysecurity News

AI-Assisted TuxBot v3 Evolution Botnet Targets IoT Devices With Modular Multi-Channel Attack Framework - CySecurity News - Latest Information Security and Hacking Incidents

Jul 15
The Hacker News

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Jul 15
Palo Alto Networks Unit 42

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.