Last seven days
- First activity
- Jul 18, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 3 IP / 0 hostnames
Gafgyt, also widely known as BASHLITE, is a long-running Linux and IoT botnet malware family primarily used to conscript internet-exposed devices into distributed denial-of-service operations.
Profile source: Mallory opens in a new tabGafgyt
Gafgyt, also widely known as BASHLITE, is a long-running Linux and IoT botnet malware family primarily used to conscript internet-exposed devices into distributed denial-of-service operations. It has historically targeted routers, cameras, DVRs, embedded Linux systems, and other poorly secured network-connected appliances, and has appeared under multiple related names in reporting, including Bashlite. The family has remained active through numerous forks and customized variants, including campaigns that target both consumer IoT and older enterprise-facing infrastructure.
Gafgyt commonly gains initial access by exploiting known vulnerabilities in exposed devices and services, and by abusing weak or default credentials on remote administration interfaces such as Telnet and SSH. Reported variants have targeted a wide range of flaws in routers, DVRs, DD-WRT firmware, SonicWall Global Management System, TP-Link Archer routers, Langflow deployments, and other internet-facing systems. Some variants use separate scanning or propagation components to identify vulnerable hosts, brute-force credentials, exploit HTTP-exposed services, or abuse exposed Android Debug Bridge interfaces, then deliver architecture-specific Linux payloads.
Once installed, Gafgyt variants typically connect to command-and-control infrastructure and await instructions to launch denial-of-service attacks. Observed capabilities include multiple flood techniques across UDP, TCP, SYN, ICMP, amplification, and HTTP-layer methods. Certain variants also implement persistence through hidden copies, cron jobs, shell profile modification, and self-relaunch behavior, while some aggressively kill competing malware and remove rival persistence artifacts to monopolize infected hosts. Defense-evasion measures such as encrypted or obfuscated command-and-control traffic have also been documented in newer customized builds.
The malware family is strongly associated with botnet activity across Linux-based embedded and IoT environments and has repeatedly been linked to large-scale DDoS campaigns. It has also served as a codebase for derivative botnets and variants used by multiple threat actors, including operations tied to broader IoT botnet ecosystems. Over time, Gafgyt-derived activity has reflected a shift from opportunistic compromise of consumer devices toward exploitation of unpatched enterprise and development infrastructure when such systems expose remotely reachable flaws.
C2 tracking
Derp observations, rolling seven-day window
Samples
95ff4b4b2e581004fca8d5767bcb6bba0c31954226f70596bc672c1af611f7fb b9f19cb9fbd83466d02d96c03f2782f0b417c69ea2196e5677626e71a8ad528d c04df8579f5a2d5eb560b20f43e31d84eedc51e36103c1cba0fb04c6e1650b4e ce9898ee2445129927a045a4a8fd8bc2d73a068c221e3ca4cbf56d0b67911b0b ffe6327d7b7ce32541251777d00704daa870a47aa4ceef79b4567146ecd249be 58a51cd77e8960e176626daca6ddcc47fe3c27428f5c50af7b4c0dd484c1e2f2 93a2c46adb598b51997c8866f4093a66922a1f7e2bfb89b7bc3c8f4eca4a8e77 97c32ae8020f03640cba5290b28348be87d26f3d444b6d2817a22bd0d9ea3be1 aa692a5a839c7a56e2cd8b70affeb4bb5252fbd9b3342d31e25208b54403941a c6568754d0ac40fc7c0ccdd98b0a4f69fd85476089161fc5eb14fbeb33949f9e Exploited software
MITRE ATT&CK
Reporting
The source code contains an IP address of 185.10.68[.]127, which we pivoted on to link TuxBot to Keksec/Kaitori (a Tsunami/Mirai/Gafgyt variant) ecosystems to a shared infrastructure.
Gafgyt3
TerraBot is an aggressive IoT botnet variant derived from Mirai and Gafgyt source code frameworks...
According to a recent Gafgyt malware analysis, the threat actors achieve initial access by targeting older software vulnerabilities.
C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks.
A newly discovered variant of the Gafgyt botnet malware, named C0XMO, has been quietly spreading across Linux-based devices by targeting a known vulnerability in DD-WRT router firmware.
In March, Labs identified a new Gafgyt botnet variant called C0XMO that spreads by exploiting CVE-2021-27137.
This past March, FortiGuard Labs discovered a new Gafgyt botnet variant, C0XMO, that spreads by exploiting CVE-2021-27137.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.