Skip to content

Gafgyt

Gafgyt, widely known as Bashlite, is a long-running Linux and IoT botnet malware family primarily used for distributed denial-of-service attacks.

Profile source: Mallory opens in a new tab

Gafgyt

Family profile

Gafgyt, widely known as Bashlite, is a long-running Linux and IoT botnet malware family primarily used for distributed denial-of-service attacks. First active in 2014, it initially spread through exploitation of Shellshock on vulnerable embedded systems and subsequently proliferated after its source code leaked in 2015. The family has many aliases, including Lizkebab, Qbot, Torlus, PinkSlip, and LizardStresser, and has produced numerous forks and derivatives.

Gafgyt commonly compromises internet-exposed routers, cameras, DVRs, GPON equipment, and other embedded Linux devices through Telnet or SSH weak-password attacks and exploitation of publicly known remote-code-execution vulnerabilities. Variants have targeted vulnerable router and IoT products from multiple vendors, and typically retrieve architecture-specific payloads following compromise. Supported architectures across variants include ARM, MIPS, PowerPC, SuperH, x86, and x64.

Infected devices communicate with command-and-control infrastructure, often using lightweight IRC-like protocols; some variants use Tor-based infrastructure to conceal command-and-control communications. Core functions include network scanning, credential brute forcing, payload retrieval, process termination to remove competing botnets, and DDoS attacks. Common attack modes include TCP, UDP, HTTP, DNS, TLS, GRE, and TCP-flag floods. Some variants also execute shell commands, use string obfuscation, impersonate legitimate process names, and establish persistence through cron jobs or shell-startup modifications. Certain newer Gafgyt-derived activity has extended beyond IoT devices to Linux servers and cloud-oriented environments, including cryptomining campaigns.

Gafgyt has been associated with multiple criminal botnet operations. Historical activity was attributed to Lizard Squad, while later Gafgyt variants and related botnets have been linked to the Keksec cybercrime ecosystem. Its leaked codebase has also materially influenced related botnets, including Hakai, Simps, Enemybot, and other Linux IoT malware families.

Capabilities

  • Brute Force
  • Crypto Theft
  • Ddos
  • Defense Evasion
  • Initial Access
  • Persistence
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 3, 2026
Last activity
Sep 9, 2026
Feed role
C2 / Distribution
Host form
8 IP / 1 hostnames

Leading locations

  • NL4
  • DE2
  • BG1
  • LU1
  • PA1

Leading providers

  • Storm Industries LLC3
  • ALEXHOST SRL1
  • Ghosty Networks LLC1
  • Panamaserver.com1
  • Pfcloud UG1
  • Philip Fjaera trading as PFWeb Solutions1

Infrastructure traits

  • Hosting 9

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
keksec group

Gafgyt_tor share the same origin with the Gafgyt samples described by the keksec group, the core function is still DDoS attacks and scanning.

vDOS

The original Mirai was consistently tweaked to compete with its “DDoS-as-a-Service” provider rival vDOS and their Gafgyt botnet.

Keksec

Keksec actively maintains three main families, Gafgyt, Tsunami and Necro, with new features constantly being added.

Lizard Squad

BASHLITE (also known as Gafgyt, Lizkebab, PinkSlip, Qbot, Torlus and LizardStresser) is malware which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS).

Exploited software

Vulnerabilities linked to Gafgyt

23 CVEs

MITRE ATT&CK

Gafgyt in ATT&CK

61 distinct techniques

Techniques

61 techniques
T1562.001 Disable or Modify Tools T1057 Process Discovery T1105 Ingress Tool Transfer T1046 Network Service Discovery T1082 System Information Discovery T1110.001 Password Guessing T1053.003 Cron T1564.001 Hidden Files and Directories T1037 Boot or Logon Initialization Scripts T1071 Application Layer Protocol T1498 Network Denial of Service T1190 Exploit Public-Facing Application T1110 Brute Force T1587.001 Malware T1203 Exploitation for Client Execution T1070 Indicator Removal T1219 Remote Access Tools T1499 Endpoint Denial of Service T1059 Command and Scripting Interpreter T1595.002 Vulnerability Scanning T1027 Obfuscated Files or Information T1036 Masquerading T1027.002 Software Packing T1040 Network Sniffing T1090 Proxy T1090.003 Multi-hop Proxy T1059.004 Unix Shell T1568.001 Fast Flux DNS T1498.001 Direct Network Flood T1001.003 Protocol or Service Impersonation T1490 Inhibit System Recovery T1095 Non-Application Layer Protocol T1083 File and Directory Discovery T1561.001 Disk Content Wipe T1078 Valid Accounts T1497.001 System Checks T1210 Exploitation of Remote Services T1021.004 SSH T1112 Modify Registry T1498.002 Reflection Amplification T1499.001 OS Exhaustion Flood T1021 Remote Services T1595 Active Scanning T1016 System Network Configuration Discovery T1070.004 File Deletion T1485 Data Destruction T1496 Resource Hijacking T1033 System Owner/User Discovery T1489 Service Stop T1068 Exploitation for Privilege Escalation T1059.006 Python T1001 Data Obfuscation T1570 Lateral Tool Transfer T1499.003 Application Exhaustion Flood T1584.005 Botnet T1078.001 Default Accounts T1518 Software Discovery T1562 Impair Defenses T1571 Non-Standard Port T1572 Protocol Tunneling T1071.001 Web Protocols

Reporting

Research mentioning Gafgyt

Sep 3
Malware News

Creating EMBeD, the Embedded Malware Benchmark Dataset - Malware Analysis - Malware Analysis, News and Indicators

Researchers at CrySyS Lab presented EMBeD (Embedded Malware Benchmark Dataset), a proposed public benchmark intended to make IoT malware-binary detection research more reproducible and comparable. The dataset addresses reliance on proprietary collections, inconsistent malware-family labels, and undisclosed machine-learning training and test splits by providing balanced, consistently labeled samples. EMBeD extracts sample metadata, filters unreliable binaries, and derives and validates family labels using weighted VirusTotal detections and TLSH-based similarity graphs. Its proof of concept processed 67,800 MIPS IoT-malware samples and produced seven families—Mirai, Gafgyt, Hajime, Kaiji, Tsunami, DDoSTF, and Dofloo—with 100 samples per family; planned releases will expand coverage and add architectures including ARM using sources such as VirusTotal and Ukatemi's Kaibou Repo.

Sep 3
Crysys

Creating EMBeD, the Embedded Malware Benchmark Dataset - CrySyS Blog

Jul 31
Sysdig

Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig

TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.

Jul 22
Security Online Info

Gafgyt Botnet Hijacks Langflow for DDoS Attacks

Attackers are actively exploiting CVE-2025-3248, a remote code execution flaw in Langflow’s code validation API, to compromise internet-exposed AI development servers and deploy a customized Gafgyt/BASHLITE malware variant on x86_64 Linux systems. Akamai reported that the intrusion chain uses untrusted Python execution to fetch a Linux binary from a staging server, launch it from a temporary directory, and turn the host into a bot focused on distributed denial-of-service activity rather than cryptomining, persistence, or lateral movement. The malware reportedly supports multiple flood modes, including UDP, TCP, HOLD, and junk/STD, and uses a modified RC4-based cipher to obscure command-and-control traffic and hinder standard decoding. CISA added CVE-2025-3248 to its Known Exploited Vulnerabilities catalog, while GreyNoise observed hundreds of exploit source IPs targeting the flaw. Defenders are being urged to patch Langflow, isolate AI development environments, place exposed instances behind a WAF, enforce outbound filtering including blocking unauthorized traffic such as port 1337, and deploy YARA detections keyed to the malware’s distinctive cipher seed bytes.

Jul 21
Security Online Info

TuxBot v3 Evolution: LLM-Built IoT Botnet Exposed

Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnet’s source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malware’s working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.

Jul 16
Scworld

New TuxBot v3 Evolution IoT botnet framework shows signs of AI development | brief | SC Media

Jul 16
Security Affairs

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

Jul 16
Cyber Security News

New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.