GuLoader Malspam Campaign – Active IOCs
June 11, 2025ICS: Multiple Schneider Electric Products Vulnerabilities
June 11, 2025GuLoader Malspam Campaign – Active IOCs
June 11, 2025ICS: Multiple Schneider Electric Products Vulnerabilities
June 11, 2025Severity
High
Analysis Summary
Gafgyt is a type of malware that is used to conduct Distributed Denial of Service (DDoS) attacks. These attacks involve overwhelming a targeted website or server with a large amount of traffic to disrupt its normal functioning. Gafgyt malware is typically spread through phishing emails or by exploiting vulnerabilities in poorly secured Internet of Things (IoT) devices, such as routers and cameras. Once a device is infected, it can be controlled remotely by the attackers and used as part of a botnet to launch DDoS attacks. These botnets can be used to target websites or servers, and they have been used to disrupt a wide range of online services in the past. The TTPs (Tactics, Techniques, and Procedures) used by Gafgyt malware include:
- Exploiting vulnerabilities: Gafgyt malware is often spread by exploiting known vulnerabilities in IoT devices, such as routers and cameras.
- Phishing emails: Gafgyt malware can also be spread through phishing emails that contain malicious links or attachments.
- Botnet: Once a device is infected, it becomes part of a botnet controlled by the attackers, which is used to launch DDoS attacks.
- DDoS attacks: This malware is primarily used to conduct DDoS attacks, which involve overwhelming a targeted website or server with a large amount of traffic to disrupt its normal functioning.
- Evasion: The malware is also known to have an advanced evasion technique, which allows it to avoid detection by security software.
- Reconnaissance: Gafgyt malware also can scan the network and identify other vulnerable devices that can be infected and added to the botnet.
The malware is known to be modular, which allows attackers to add new capabilities to the malware as needed. This makes it a versatile threat that can be used for a wide range of attacks. Organizations should be aware of the threat posed by Gafgyt malware and take appropriate measures to protect their networks from DDoS attacks, such as implementing DDoS mitigation solutions.
Impact
- Server Outage
- Data Loss
- Website Downtime
Indicators of Compromise
MD5
638b0dd9c9c542c4701eb4079c1724e5
69a05e3ce3da505f2671fd604c4b25f4
0c5470e960b50e50fdea6d0e03643a9c
SHA-256
a580e2e811d2408084731d9da306e3fe2994143c5f79442c8084f4277a3497df
99ed85c7fcffa2e1ddbb1b2a49527f11edc5ff959cbeedb2bade01808443f19f
e88b8653feb8bf2bc16f24afae9ddc5c58ad089844b18eda0002f1ed4cbb02da
SHA-1
41fdaa6e8f80bf126ed90afcd0a9259a0576a161
64d66cb04ffae8e0757884a0a73bfd2eaeff9c0e
f4b63d9f092605432816849bd2f9f4255a16015f
Remediation
- Block all threat indicators at your respective controls.
- Search for indicators of compromise (IOCs) in your environment utilizing your respective security controls.
- Upgrade your operating system.
- Don't open files and links from unknown sources.
- Install and run anti-virus scans.