FortiGuard Labs is aware that AndroxGh0st malware is actively used in the field to primarily target .env files that contain confidential information such as credentials for various high profile applications such as – AWS, O365, SendGrid, and Twilio from the Laravel web application framework.Why is this Significant?This is significant as AndroxGh0st malware is actively used in the field to target Laravel .env files that contain sensitive information such as credentials for AWS, O365, SendGrid, and Twilio. FortiGuard Labs observes in the wild attempts by the AndroxGh0st malware more than 40,000 Fortinet devices a day.What is AndroxGh0st Malware?AndroxGh0st is a Python malware designed to search for and extract .env files from the Laravel Laravel application.AndroxGh0st supports numerous functions to abuse SMTP such as scanning and exploiting exposed credentials and APIs, and web shell deployment.What is the Status of Protection?FortiGuard Labs has the following AV signatures in place for known AndroxGh0st malware samples:Python/AndroxGhost.A!trPython/AndroxGhost.HACK!trPHP/AndroxGhost.AZZA!trW32/AndroxGhost.HACK!trW32/AndroxGhost.BEAE!trMSIL/AndroxGhost.HACK!trFortiGuard Labs has the following IPS signature in place for AndroxGh0st:AndroxGh0st.Malware
More Stories
mariadb-10.5.20-1.fc38
FEDORA-2023-381f23a0ae Packages in this update: mariadb-10.5.20-1.fc38 Update description: MariaDB 10.5.20 Release notes: https://mariadb.com/kb/en/mariadb-10-5-20-release-notes/ Read More
mariadb-10.5.20-1.fc37
FEDORA-2023-b4ff407364 Packages in this update: mariadb-10.5.20-1.fc37 Update description: MariaDB 10.5.20 Release notes: https://mariadb.com/kb/en/mariadb-10-5-20-release-notes/ Read More
Defense in depth — the Microsoft way (part 85): escalation of privilege plus remote code execution with HVCISCAN.exe
Posted by Stefan Kanthak on Jun 07 Hi @ll, about a month ago Microsoft published HVCIScan-{amd,arm}64.exe, a "Tool to check...
LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863
Posted by Qualys Security Advisory via Fulldisclosure on Jun 07 Qualys Security Advisory LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864,...
matrix-synapse-1.85.1-1.fc38
FEDORA-2023-e191040276 Packages in this update: matrix-synapse-1.85.1-1.fc38 Update description: Update to v1.85.1 Update to v1.85.0 Fixes CVE-2023-32682, CVE-2023-32683 Update to v1.84.1...
USN-6145-1: Sysstat vulnerabilities
It was discovered that Sysstat incorrectly handled certain arithmetic multiplications. An attacker could use this issue to cause Sysstat to...