Last seven days
- First activity
- Aug 13, 2026
- Last activity
- Aug 13, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 0 hostnames
Gafgyt, also widely known as BASHLITE, is a long-running Linux and IoT botnet malware family primarily used to conscript vulnerable devices into distributed denial-of-service operations.
Profile source: Mallory opens in a new tabGafgyt
Gafgyt, also widely known as BASHLITE, is a long-running Linux and IoT botnet malware family primarily used to conscript vulnerable devices into distributed denial-of-service operations. It has historically targeted embedded Linux systems such as routers, cameras, DVRs, and other internet-exposed appliances, and newer variants have also been observed targeting enterprise-facing Linux infrastructure and AI development servers. The family is notable for extensive code reuse and branching, with many variants and related strains sharing overlapping functionality, exploit modules, and infrastructure patterns.
Gafgyt commonly gains initial access by exploiting known vulnerabilities in exposed devices and services, and some variants also use credential attacks against weakly secured remote administration interfaces. Observed campaigns have targeted router and IoT flaws as well as enterprise software vulnerabilities, including exploitation of Langflow remote code execution to deploy a stripped-down DDoS-focused payload on x86_64 Linux servers, exploitation of older SonicWall GMS vulnerabilities, and exploitation of DD-WRT UPnP flaws by the C0XMO variant. Several variants deliver architecture-specific Linux binaries to maximize infection success across heterogeneous hardware.
Its core purpose is botnet enrollment and remote attack execution. Gafgyt variants typically connect to command-and-control infrastructure and await instructions to launch network flooding attacks. Documented capabilities include multiple DDoS methods such as UDP, TCP, SYN, ICMP, HTTP-layer floods, HOLD-style attacks, and amplification techniques in some variants. Certain branches also include scanning modules, update mechanisms, process killing to remove competing malware, and persistence through cron jobs, shell profile modification, hidden copies, or watchdog-style relaunch behavior. Other observed variants are more minimal and omit persistence, lateral movement, or secondary monetization features in favor of pure flooding capability.
The malware family has been linked over time to a broad ecosystem of criminal botnet activity rather than a single stable operator. Variants and derivative botnets such as C0XMO, TerraBot, and other Gafgyt-based strains have been observed in campaigns targeting unmanaged IoT fleets, small-office and home-office equipment, and occasionally enterprise systems. Gafgyt remains relevant because old source code, modular reuse, and the continued exposure of unpatched Linux-based devices allow operators to rapidly adapt the family to new exploits and targets.
C2 tracking
Derp observations, rolling seven-day window
Samples
1ece38f76d2242025915a4c8e1373d07b372f4d54844dfe1d1fc4568bdbf0f4b 32f28732b38c43553192b27e648c079b1cbd24372426083ebc6ab96065ed577b 5d69b801926d789d11b2d77e01c6fc6c0939a7fe070d5a31dc00c99d754db43a 93b2b10275c52ea32e58e6265bbbbbef309283c2193f193c288443e1560651f7 ee223d4c46acb576bb9d3a0f371431cbbc1336ecf403dd75ab3a073fe7f3c811 02d70eb6accd3567b63b1841e22c9646dabca3f01ab8eb021a2e666e4e0fa233 07d24f98d34ebcd0e8fe40ea9218805c94dd500e4ed3c3a0cebf79692aa53802 408026ea525490fd64312ace9e65d433ce6f0f43f3ae833834261aade507c2d6 4fc97f256de9e479b9befc4de3afa6a9236672605f3215e37869ae173fb6b281 b8c508760c9a35304b17ac4156b93ee76b6b57bb05e2426c5f9912b65ffea0bd Exploited software
MITRE ATT&CK
Reporting
Attackers are actively exploiting CVE-2025-3248, a remote code execution flaw in Langflow’s code validation API, to compromise internet-exposed AI development servers and deploy a customized Gafgyt/BASHLITE malware variant on x86_64 Linux systems. Akamai reported that the intrusion chain uses untrusted Python execution to fetch a Linux binary from a staging server, launch it from a temporary directory, and turn the host into a bot focused on distributed denial-of-service activity rather than cryptomining, persistence, or lateral movement. The malware reportedly supports multiple flood modes, including UDP, TCP, HOLD, and junk/STD, and uses a modified RC4-based cipher to obscure command-and-control traffic and hinder standard decoding. CISA added CVE-2025-3248 to its Known Exploited Vulnerabilities catalog, while GreyNoise observed hundreds of exploit source IPs targeting the flaw. Defenders are being urged to patch Langflow, isolate AI development environments, place exposed instances behind a WAF, enforce outbound filtering including blocking unauthorized traffic such as port 1337, and deploy YARA detections keyed to the malware’s distinctive cipher seed bytes.
Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnet’s source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malware’s working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.