WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships CISA and FBI Release Known IOCs Associated with Androxgh0st Malware
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

CISA and FBI Release Known IOCs Associated with Androxgh0st Malware

Author: Alec Davison

Created: Tuesday, January 16, 2024 - 20:11

Categories: Cybersecurity

Today, CISA and the FBI released a joint Cybersecurity Advisory (CSA), “Known Indicators of Compromise Associated with Androxgh0st Malware,” to provide network defenders with known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with threat actors deploying Androxgh0st malware.

According to the advisory, Androxgh0st malware establishes a botnet to scan for websites using the Laravel web application framework. On these websites, threat actors have attempted to determine if the domain’s root-level .env file is exposed and if they contain credentials for accessing additional services. Multiple investigations are reportedly ongoing regarding Androxgh0st malware’s capability to establish a botnet and further identify and compromise vulnerable networks. CISA and the FBI state that “threat actors exploiting Androxgh0st malware have been observed exploiting specific vulnerabilities which could lead to remote code execution; those common vulnerabilities and exposures (CVE) are CVE-2017-9841 (PHP Unit Command), CVE-2021-41773 (Apache HTTP Server versions) and CVE-2018-15133 (Laravel applications).”

CISA and the FBI recommend network defenders prioritize patching known exploited vulnerabilities in internet-facing systems, review and ensure only necessary servers and services are exposed to the Internet, and review platforms or services that have credentials listed in .env files for unauthorized access or use. Lastly, CISA and the FBI urge every organization to review the advisory, implement recommended mitigations, and validate your organization’s security controls against the threat behaviors mapped to the MITRE ATT&CK. Access the full advisory at CISA.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 7, 2026)

May 7, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:GREEN) Gate 15 TARGET Report – Identity Centric Attacks: The Shift from Network to Identity as the Primary Attack Surface

May 7, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) CISA and Partners Release Guidance for Careful Adoption of Agentic AI Services

May 7, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar