Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Gafgyt

115
Global rank
87 infographic chevron month
Month rank
160 infographic chevron week
Week rank
0
IOCs

Gafgyt, also known as BASHLITE, is a botnet affecting Internet of Things (IoT) devices and Linux-based systems. The malware aims to compromise and gain control of these devices, often by exploiting weak or default passwords, as well as known vulnerabilities. Gafgyt has been around since 2014 and has evolved into multiple variants, each with its own set of features and capabilities, including the ability to launch distributed denial of service (DDoS) attacks.

Botnet
Type
Unknown
Origin
1 September, 2014
First seen
7 September, 2026
Last seen
Also known as
BASHLITE
LizardStresser
Torlus

How to analyze Gafgyt with ANY.RUN

Type
Unknown
Origin
1 September, 2014
First seen
7 September, 2026
Last seen

IOCs

IP addresses
131.123.40.104
151.101.194.49
91.189.91.57
185.125.190.56
185.125.190.57
89.32.41.31
151.101.193.91
85.214.83.151
151.101.1.91
151.101.65.91
151.101.129.91
31.209.85.243
91.189.91.97
185.125.190.100
128.140.109.119
85.215.227.11
217.154.242.97
91.189.91.98
185.125.190.99
88.198.7.62
Hashes
8f7a3c8df5f9e467b8e4645ae07856b53ba16ac53e2b5de85f07eb61deaddd76
163582db1c9f586d178686343668a5d16af7a64d7bebc5e969948eedbddf8206
edc3f61193ba8d5d4941334360b8c8141b308fbb12c5b9edf4417b76d1c2faf7
3aea28dce9986a41162613578b287deb73d0e197ba618306d525353bc7297c9a
c803042bf66413ba4a5dfb3a305e322a36ed9e698389cc39efd58364ba30ce5d
8e06754e5e64bdf5f61dd604a5f12e9bc10f5502316b5379fb258f84a5d84702
30c7d351e70323915566d2bb648b4313c9722b34252929a8c7050f6495ae14fc
7cc0b40e8819ec9139ffae5942add2db1c26e168edaeda57302c9047f23dfb6c
9fca540b88a7ea5dc0890c567e844003cdc43977f4a93d7cdee8fdd7f91c2f4b
0a303df379fd147b55442d958ccb6a8b9ab1d1ddac8e7aa4fc4647b796815c41
e914bd76c24431fdfbe2c5f40a00aef6a679668b730b5a07ec8e4db2d03acd32
75f25efbeb8860ba480b4375315a990c7d9d9479412be52e559762623ca5dd53
2364f5ebe71bd534cdceaea8886bacc10288badd29ca283ef75f42311bfb42c4
18e70075f12c9ca0ff6d123924ee4f4b62ba58facc1236d61199ed18778e1726
dc004a28370459a98ba6819a51a79d4b4b9c965b7789b2aef8733c70241c2dcd
0bdaab30a5c5d6915f3f619532963fdeb42a3e0fa2120bb71bcba75def6fe953
4a4c2aa65ef16090f52d26970da58ea304d60b7309a45eea0cdbe56feac58a16
7c75325375e2decd83d767d14c853c1df8d022d9c4f5017474902fe143a94fea
6075d06b971f4ea2f57d7bae71106c4d8b77ec6e9f4931ef7d447d27bcb6a108
5c77f676b8d5d1d70e22261b185d6e30068722c40005dd2aad6ea656be3eed14
Domains
google.com
connectivity-check.ubuntu.com
cdn.fwupd.org
ntp.ubuntu.com
s467326833rgjs.ddns.net
odrs.gnome.org
api.snapcraft.io
archive.ubuntu.com
files.pythonhosted.org
dl.google.com
ppa.launchpadcontent.net
motd.ubuntu.com
esm.ubuntu.com
archive.canonical.com
pypi.org
chromewebstore.googleapis.com
update.googleapis.com
content-autofill.googleapis.com
duckduckgo.com
android.clients.google.com
URLs
http://connectivity-check.ubuntu.com/
http://131.123.40.104/ghfjfgvj
http://131.123.40.104/jipjipjj
http://131.123.40.104/jhuoh
http://131.123.40.104/ryrydry
http://131.123.40.104/uyyuyioy
http://131.123.40.104/xdzdfxzf
http://131.123.40.104/jipjuipjh
http://131.123.40.104/dfhxdhdf
http://131.123.40.104/fdfdhfc
http://131.123.40.104/ftudftui
http://131.123.40.104/bins.sh
http://41.216.189.157/bins/xnxnxnxnxnxnxnxni386xnxn
http://85.204.125.67/a-r.m-8.sativac2
http://85.204.125.67/m-p.s-l.sativac2
http://85.204.125.67/a-r.m-7.sativac2
http://85.204.125.67/m-i.p-s.sativac2
http://85.204.125.67/x-8.6-.sativac2
https://pypi.org/simple/psutil/
https://pypi.org/simple/watchdog/
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 5013
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 9976
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 11821
comments 0

What is Gafgyt malware?

Gafgyt, also known as BASHLITE, LizardStresser, and Torlus, is a malware family that targets Linux-based IoT devices such as routers and IP cameras. It is known for its botnet capabilities, which allow it to conduct DDoS attacks and perform other malicious activities.

Gafgyt has been active since at least 2014, when it was initially named Bashdoor. Over the years, it has been responsible for multiple high-profile DDoS attacks. For instance, in 2019, the botnet was used to disrupt the operations of Valve Source Engine and games like Fortnine by targeting their servers.

The prevalence of this malware can be attributed to the fact that its original code was exposed to the public in 2015. Since then, different threat actors have used it to build their own strains of the malware and employed them in numerous attacks.

Gafgyt execution process

We can study the behavior of Gafgyt on an infected system by analyzing its sample in ANY.RUN’s cloud malware sandbox.

We are going to use an .elf file sample, which is an executable format on Linux systems commonly used by attackers to distribute Gafgyt. View the analysis session by following this link.

Gafgyt analysis in ANY.RUN Gafgyt analysis in ANY.RUN

After launching the analysis, the service instantly detects Gafgyt and starts to record all of its malicious activities.

When looking at the Connections tab, we can see how the infected machine joins a botnet and participates in a DDoS attack. Specifically, the sandbox shows how the machine begins making thousands of connections.

Gafgyt analysis in ANY.RUN ANY.RUN also provides the Suricata rule which was used to detect Gafgyt

When exploring the Threats tab, we can observe the Suirata rules which were triggered during the analysis process. We can click on each one to access more details.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Gafgyt malware technical details

Gafgyt is written in C programming language. It uses a modular structure, which allows it to dynamically load and execute plugins. Interestingly, some of the versions of Gafgyt utilize code originally found in the Mirai malware, including TCP and HTTP flooding modules.

The primary way used by Gafgyt to hijack IoT devices is through brute forcing. The malware has a hard-coded list of default Telnet and SSH credentials which it employs in its attempts to penetrate devices.

Another method of infecting devices utilized by Gafgyt is through vulnerabilities. For instance, CVE-2017-18368 is one of the flaws exploited by the malware to target Zyxel routers. It is possible because of a lack of proper input validation in the Remote System Log forwarding function.

CVE-2023-1389 is another vulnerability abused by the most recent variants of Gafgyt. It is present on TP-Link Archer devices and once again involves the execution of an unauthorized malicious command that can be added to the country form in the web management interface.

After infecting the device, Gafgyt usually downloads a script from a pre-configured address and launches it. After collecting the device’s IP address and system information, it connects to its command-and-control server (C2).

Next, the C2 may send instructions to the malware which usually include engaging in different types of flooding attacks on specified targets.

The malware uses a combination of symmetric and asymmetric encryption for its communication.The malware's C2 servers are typically hosted on compromised devices.

Some versions of Gafgyt also have a persistence mechanism that allows it to survive device reboots.

Gafgyt malware distribution methods

Unlike botnet malware such as Socks5Systemz that spreads via loaders, Gafgyt is usually distributed through exploitation of security flaws in IoT devices. This can include devices with open Telnet or SSH ports, devices with default or weak credentials, and devices that have not been patched for known vulnerabilities.

It also has a self-propagation mechanism, which allows it to spread to other devices without any user interaction. This is typically done by scanning the internet for devices with open ports and attempting to gain access using default credentials.

The malware can also be distributed through malicious downloads. This can occur when a user downloads and executes a file from an untrusted source, such as a malicious website or email attachment.

How to analyze BASHLITE malware

Despite being decade-old, Gafgyt continues to be a considerable threat. It is particularly serious for organizations with Linux-based infrastructure. Protecting against a Gafgyt infection requires a combination of security measures, including strong unique passwords and timely patching.

To understand how Gafgyt and other malware operate, as well as to collect indicators of compromise, use ANY.RUN’s interactive sandbox.

The service is invaluable for malware analysts and SOC professionals, as it:

  • Detects threats in files and links in under 40 seconds.
  • Lets you interact with the samples and the system just like with a standard computer.
  • Offers customizable Windows and Linux virtual machines.
  • Generates comprehensive threat reports.
  • Exposes all malicious network, registry, & files activity and processes.

With ANY.RUN, you can strengthen your security posture.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
Phantom Stealer screenshot
Phantom Stealer
phantomstealer
Phantom Stealer is a commercially available Malware-as-a-Service infostealer targeting Windows systems. It harvests browser passwords, session cookies, payment data, cryptocurrency wallets, system information, screenshots, and application data.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
Grandoreiro screenshot
Grandoreiro
grandoreiro
Grandoreiro is a Latin American banking trojan first observed in 2016. It targets mostly Spanish-speaking countries, such as Brazil, Spain, Mexico and Peru. This malware is operated as a Malware-as-a-Service (MaaS), which makes it easily accessible for cybercriminals. Besides, it uses advanced techniques to evade detection.
Read More