Bashlite

Aliases: Gafgyt, gayfgt, lizkebab, qbot, torlus

First seen
2014-09-01 00:00:00
Malware type
ddos, botnet
Family
Malware family
Last IoC activity
2026-07-22 03:35:18
Profile updated
2026-07-07 13:05:49

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.

Detection coverage

  • 2 YARA rules

Exploited vulnerabilities

  • CVE-2020-8218 (vulnerability)
  • CVE-2022-22954 (vulnerability)

Detection rules

  • SIGNATURE_BASE_MAL_Qbot_HTML_Smuggling_Indicators_Oct22_1 (yara-rule)
  • MALPEDIA_Elf_Bashlite_Auto (yara-rule)

Related threat objects

  • Gafgyt (infrastructure)

Reports & references

  • blog.netlab.360.com — Gafgtyt Tor And Necro Are On The Move Again (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Bashlite (report)
  • avira.com — A Gafgyt Variant That Exploits Pulse Secure Cve 2020 8218 (report)
  • Palo Alto Unit 42 — Cve 2022 22954 Vmware Vulnerabilities (report)
  • blog.netlab.360.com — Some Details Of The Ddos Attacks Targeting Ukraine And Russia In Recent Days (report)
  • aquasec.com — Gafgyt Malware Variant Exploits Gpu Power And Cloud Native Environments (report)
  • maxkersten.nl — Corona Ddos Bot (report)
  • cybersecurity.att.com — Code Similarity Analysis With R2Diaphora (report)
  • blog.netlab.360.com — Wo Men Kan Dao De Wu Ke Lan Bei Ddosgong Ji Xi Jie (report)
  • blog.netlab.360.com — The Gafgyt Variant Vbot And Its 31 Campaigns (report)
  • vb2020.vblocalhost.com — Vb2020 Liu (report)
  • krebsonsecurity.com — Krebsonsecurity Hit With Record Ddos (report)
  • uptycs.com — Discovery Of Simps Botnet Leads Ties To Keksec Group (report)
  • Palo Alto Unit 42 — New Hoaxcalls Ddos Botnet (report)
  • blog.cyber5w.com — Gafgyt Backdoor Analysis (report)
  • uptycs.com — Mirai Code Re Use In Gafgyt (report)
  • Palo Alto Unit 42 — Unit42 Multi Exploit Iotlinux Botnets Mirai Gafgyt Target Apache Struts Sonicwall (report)
  • virusbulletin.com — Kalnaihorejsi Vb2015 (report)
  • blackberry.com — Report Bb 2021 Threat Report (report)
  • Palo Alto Unit 42 — Hoaxcalls Mirai Target Legacy Symantec Web Gateways (report)
  • cujo.com — Mirai Gafgyt With New Ddos Modules Discovered (report)
  • blog.netlab.360.com — Public Cloud Threat Intelligence 202203 (report)
  • Trend Micro — Bashlite Affects Devices Running On Busybox (report)
  • nozominetworks.com — Could Threat Actors Be Downgrading Their Malware To Evade Detection (report)

External references