CyberzSOC

Publication detail
← Back to advisories & guidance

CISA and FBI Release Known IOCs Associated with Androxgh0st Malware ↗ source

January 16, 2024 CISA Alert
Co-sealed by: CISA, FBI

Summary

Androxgh0st malware establishes a botnet for victim identification and exploitation in vulnerable networks, and targets files that contain confidential information, such as credentials, for various high profile applications. Threat actors deploying Androxgh0st malware have been observed exploiting specific vulnerabilities which could lead to remote code execution, including: CVE-2017-9841 (PHP Unit Command) CVE-2021-41773 (Apache HTTP Server versions), and CVE-2018-15133 (Laravel applications). In response, CISA is adding these CVEs to its Known Exploited Vulnerabilities Catalog . This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2017-9841 9.8 Critical PHPUnit PHPUnit PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on…
CVE-2018-15133 8.1 High Laravel Laravel Framework Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be e…
CVE-2021-41773 7.5 High Apache HTTP Server Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories conf…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.