Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Gafgyt

109
Global rank
79 infographic chevron month
Month rank
53 infographic chevron week
Week rank
0
IOCs

Gafgyt, also known as BASHLITE, is a botnet affecting Internet of Things (IoT) devices and Linux-based systems. The malware aims to compromise and gain control of these devices, often by exploiting weak or default passwords, as well as known vulnerabilities. Gafgyt has been around since 2014 and has evolved into multiple variants, each with its own set of features and capabilities, including the ability to launch distributed denial of service (DDoS) attacks.

Botnet
Type
Unknown
Origin
1 September, 2014
First seen
22 August, 2026
Last seen
Also known as
BASHLITE
LizardStresser
Torlus

How to analyze Gafgyt with ANY.RUN

Type
Unknown
Origin
1 September, 2014
First seen
22 August, 2026
Last seen

IOCs

IP addresses
151.101.129.91
31.209.85.243
151.101.193.91
151.101.65.91
151.101.1.91
91.189.91.97
185.125.190.56
185.125.190.57
185.125.190.100
128.140.109.119
85.215.227.11
217.154.242.97
91.189.91.98
185.125.190.99
88.198.7.62
91.189.91.96
173.249.58.145
185.248.189.10
185.41.106.152
185.125.190.101
Hashes
0bdaab30a5c5d6915f3f619532963fdeb42a3e0fa2120bb71bcba75def6fe953
4a4c2aa65ef16090f52d26970da58ea304d60b7309a45eea0cdbe56feac58a16
7c75325375e2decd83d767d14c853c1df8d022d9c4f5017474902fe143a94fea
2a324a37f047c7ac1366328c7f9c239f7d1d834fd98994e501fd935ee3eec1d9
349053fad80b02f4e88188c0e5aaf861a07d830b7529575ab76e8cdc4c989e84
6b864a73cf471fe526be9ebe9fd444e3919c45aedab1e43d8a42d5801efd908c
c0111291f4dfeba09099cfcbd07930830cb13360365404152b18fc85d77e1ac7
fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
18e70075f12c9ca0ff6d123924ee4f4b62ba58facc1236d61199ed18778e1726
dc004a28370459a98ba6819a51a79d4b4b9c965b7789b2aef8733c70241c2dcd
06fb65222f6b6628c6892f6f7a1c8d71de467eee869838b407575745cb5a062a
e06d110324cf8a23b160aa2ae2d8002ab076d5ddbf33684c7cc36919f8cd10d0
c04df8579f5a2d5eb560b20f43e31d84eedc51e36103c1cba0fb04c6e1650b4e
53264b4ed421f9dc508fe0637c6a6ef33ef01968fde6b7ba6602c985bcc3868f
fdc1a16d5fd9124c4e413a76ed08fd308d64e7c5cf962b5d3456d64798727afa
b9f19cb9fbd83466d02d96c03f2782f0b417c69ea2196e5677626e71a8ad528d
e0754e66eb4a2e6267ddb4af0a15cad48a8acd725e74a0a96121e7aaf943dafb
e1f14ce35b44d79506493faafb33c194732278c76cf0b0424579d0dd692b4388
ffe6327d7b7ce32541251777d00704daa870a47aa4ceef79b4567146ecd249be
422aa53f36b86584e56eaf4f7f67c4b5d45718e1d27d4f3c9fbceb20ebe26889
Domains
google.com
connectivity-check.ubuntu.com
cdn.fwupd.org
ntp.ubuntu.com
s467326833rgjs.ddns.net
odrs.gnome.org
api.snapcraft.io
archive.ubuntu.com
files.pythonhosted.org
dl.google.com
ppa.launchpadcontent.net
motd.ubuntu.com
esm.ubuntu.com
archive.canonical.com
pypi.org
chromewebstore.googleapis.com
update.googleapis.com
content-autofill.googleapis.com
duckduckgo.com
android.clients.google.com
URLs
http://connectivity-check.ubuntu.com/
http://41.216.189.157/bins/xnxnxnxnxnxnxnxni386xnxn
http://85.204.125.67/a-r.m-8.sativac2
http://85.204.125.67/m-p.s-l.sativac2
http://85.204.125.67/a-r.m-7.sativac2
http://85.204.125.67/m-i.p-s.sativac2
http://85.204.125.67/x-8.6-.sativac2
https://pypi.org/simple/psutil/
https://pypi.org/simple/watchdog/
https://files.pythonhosted.org/packages/b5/70/5d8df3b09e25bce090399cf48e452d25c935ab72dad19406c77f4e828045/psutil-7.2.2-cp36-abi3-manylinux2010_x86_64.manylinux_2_12_x86_64.manylinux_2_28_x86_64.whl
https://files.pythonhosted.org/packages/b5/e8/dbf020b4d98251a9860752a094d09a65e1b436ad181faf929983f697048f/watchdog-6.0.0-py3-none-manylinux2014_x86_64.whl
https://pypi.org/simple/scapy/
https://files.pythonhosted.org/packages/f0/6f/bd32e5e8adc391063858da17271bb444e4b009842cffa593bca8b2b78af7/scapy-2.7.0-py3-none-any.whl
http://archive.ubuntu.com/ubuntu/dists/jammy-updates/inrelease
http://archive.canonical.com/ubuntu/dists/jammy/inrelease
http://archive.ubuntu.com/ubuntu/dists/jammy/inrelease
http://archive.ubuntu.com/ubuntu/dists/jammy-security/inrelease
http://archive.ubuntu.com/ubuntu/dists/jammy-backports/inrelease
http://archive.ubuntu.com/ubuntu/dists/jammy/main/binary-amd64/by-hash/sha256/37cb57f1554cbfa71c5a29ee9ffee18a9a8c1782bb0568e0874b7ff4ce8f9c11
http://archive.ubuntu.com/ubuntu/dists/jammy/main/binary-i386/by-hash/sha256/899066c13d1ea78bfe577b1acb26db3a0641385159c0f1a938ab66b8b30c54f4
Last Seen at

Recent blog posts

post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 1206
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 7344
comments 0
post image
Hunt Malware & Phishing Threats with ANY....
watchers 7035
comments 0

What is Gafgyt malware?

Gafgyt, also known as BASHLITE, LizardStresser, and Torlus, is a malware family that targets Linux-based IoT devices such as routers and IP cameras. It is known for its botnet capabilities, which allow it to conduct DDoS attacks and perform other malicious activities.

Gafgyt has been active since at least 2014, when it was initially named Bashdoor. Over the years, it has been responsible for multiple high-profile DDoS attacks. For instance, in 2019, the botnet was used to disrupt the operations of Valve Source Engine and games like Fortnine by targeting their servers.

The prevalence of this malware can be attributed to the fact that its original code was exposed to the public in 2015. Since then, different threat actors have used it to build their own strains of the malware and employed them in numerous attacks.

Gafgyt execution process

We can study the behavior of Gafgyt on an infected system by analyzing its sample in ANY.RUN’s cloud malware sandbox.

We are going to use an .elf file sample, which is an executable format on Linux systems commonly used by attackers to distribute Gafgyt. View the analysis session by following this link.

Gafgyt analysis in ANY.RUN Gafgyt analysis in ANY.RUN

After launching the analysis, the service instantly detects Gafgyt and starts to record all of its malicious activities.

When looking at the Connections tab, we can see how the infected machine joins a botnet and participates in a DDoS attack. Specifically, the sandbox shows how the machine begins making thousands of connections.

Gafgyt analysis in ANY.RUN ANY.RUN also provides the Suricata rule which was used to detect Gafgyt

When exploring the Threats tab, we can observe the Suirata rules which were triggered during the analysis process. We can click on each one to access more details.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Gafgyt malware technical details

Gafgyt is written in C programming language. It uses a modular structure, which allows it to dynamically load and execute plugins. Interestingly, some of the versions of Gafgyt utilize code originally found in the Mirai malware, including TCP and HTTP flooding modules.

The primary way used by Gafgyt to hijack IoT devices is through brute forcing. The malware has a hard-coded list of default Telnet and SSH credentials which it employs in its attempts to penetrate devices.

Another method of infecting devices utilized by Gafgyt is through vulnerabilities. For instance, CVE-2017-18368 is one of the flaws exploited by the malware to target Zyxel routers. It is possible because of a lack of proper input validation in the Remote System Log forwarding function.

CVE-2023-1389 is another vulnerability abused by the most recent variants of Gafgyt. It is present on TP-Link Archer devices and once again involves the execution of an unauthorized malicious command that can be added to the country form in the web management interface.

After infecting the device, Gafgyt usually downloads a script from a pre-configured address and launches it. After collecting the device’s IP address and system information, it connects to its command-and-control server (C2).

Next, the C2 may send instructions to the malware which usually include engaging in different types of flooding attacks on specified targets.

The malware uses a combination of symmetric and asymmetric encryption for its communication.The malware's C2 servers are typically hosted on compromised devices.

Some versions of Gafgyt also have a persistence mechanism that allows it to survive device reboots.

Gafgyt malware distribution methods

Unlike botnet malware such as Socks5Systemz that spreads via loaders, Gafgyt is usually distributed through exploitation of security flaws in IoT devices. This can include devices with open Telnet or SSH ports, devices with default or weak credentials, and devices that have not been patched for known vulnerabilities.

It also has a self-propagation mechanism, which allows it to spread to other devices without any user interaction. This is typically done by scanning the internet for devices with open ports and attempting to gain access using default credentials.

The malware can also be distributed through malicious downloads. This can occur when a user downloads and executes a file from an untrusted source, such as a malicious website or email attachment.

How to analyze BASHLITE malware

Despite being decade-old, Gafgyt continues to be a considerable threat. It is particularly serious for organizations with Linux-based infrastructure. Protecting against a Gafgyt infection requires a combination of security measures, including strong unique passwords and timely patching.

To understand how Gafgyt and other malware operate, as well as to collect indicators of compromise, use ANY.RUN’s interactive sandbox.

The service is invaluable for malware analysts and SOC professionals, as it:

  • Detects threats in files and links in under 40 seconds.
  • Lets you interact with the samples and the system just like with a standard computer.
  • Offers customizable Windows and Linux virtual machines.
  • Generates comprehensive threat reports.
  • Exposes all malicious network, registry, & files activity and processes.

With ANY.RUN, you can strengthen your security posture.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

Remcos screenshot
Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.
Read More
Octo screenshot
Octo
octo coper
Octo malware, also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.
Read More
Salty 2FA screenshot
Salty 2FA
salty2fa
Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.
Read More
Phishing kit screenshot
Phishing kit
tycoon evilproxy sneaky2fa
Phishing kits are pre-packaged sets of malicious tools designed to make it easy for cybercriminals to launch phishing attacks. These kits replicate legitimate websites, steal credentials, and often include backend infrastructure for managing stolen data.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
NetSupport RAT screenshot
NetSupport RAT
netsupport
NetSupport RAT is a malicious adaptation of the legitimate NetSupport Manager, a remote access tool used for IT support, which cybercriminals exploit to gain unauthorized control over systems. It has gained significant traction due to its sophisticated evasion techniques, widespread distribution campaigns, and the challenge it poses to security professionals who must distinguish between legitimate and malicious uses of the underlying software.
Read More