Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Senate passes landmark genius law stablecoin bill

Florida State Legislatures Pass Charter School Expansion

OpenAI’s AI Technology to Revolutionize Military Operations?

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » New flodrix botnet variant exploits langflow ai server rce bug to launch DDOS attacks
Identity

New flodrix botnet variant exploits langflow ai server rce bug to launch DDOS attacks

userBy userJune 17, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 17, 2025Ravi LakshmananBotnet/Vulnerability

New flodrix botnet variant

Cybersecurity researchers have called attention to a new campaign that will actively leverage the critical security flaws recently disclosed on Langflow to provide Flodrix BotNet malware.

“Attackers use the vulnerability to run downloader scripts on the compromised Langflow server to retrieve and install Flodrix malware,” Trend Micro researchers Aliakbar Zahravi, Ahmed Mohamed Ibrahim, Sunil Bharti and Shubham Singh said in a technical report released today.

This activity involves exploitation of CVE-2025-3248 (CVSS score: 9.8). This lacks the authentication vulnerability in Langflow, a Python-based “visual framework” for building artificial intelligence (AI) applications.

Cybersecurity

The successful exploitation of the flaws allows uncertified attackers to execute arbitrary code via created HTTP requests. Patched by Langflow in version 1.3.0 in March 2025.

Last month, the US Cybersecurity and Infrastructure Security Agency (CISA) flagged the aggressive exploitation of CVE-2025-3248 in the wild, and the SANS Technology Institute revealed it had detected attempts to exploit against honeypot servers.

The latest findings from Trend Micro show that threat actors are conducting reconnaissance to leverage published proof of concept (POC) code and “targeting unearned internet exposed Langflow instances that leverage public proof of concept (POC) code to drop shell script downloaders responsible for obtaining and running Frodricksbotnet malware from 80.66.75.”[.]121:25565. ”

Once installed, FLODRIX configures communication with a remote server that receives commands over TCP to invoke a distributed deny (DDOS) attack on the target target IP address. The botnet also supports connections over the Tor Anonymous Network.

“LangFlow does not force input validation or sandboxes, so these payloads are compiled and executed within the context of the server. [remote code execution]”Based on these steps, attackers are likely to be profiled all vulnerable servers, using the data collected to identify high-value targets for future infections.”

Trend Micro identified unknown threat actors hosting different download device scripts on the same host used to fetch Flodrix, suggesting that the campaign is doing aggressive development.

Cybersecurity

Flodrix is ​​rated as an evolution of another botnet called Leethozer, linked to the Moobot group. The improved variant incorporates the ability to carefully remove command and control (C2) server addresses and other important metrics, minimizing forensic traces and complicating analytical efforts.

“Another important change is the introduction of a new DDOS attack type, which is now encrypted and has added a layer of observation,” Trend Micro said. “The new sample enumerates the running processes by opening the /Proc directory to access all running processes.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOuternet London cracks live audience measurement codes
Next Article Over a third of UK companies are not dangerously prepared for AI risks
user
  • Website

Related Posts

Google Chrome Zero-Day CVE-2025-2783 Taxoff exploits Trinper Backdoor

June 17, 2025

A bug in Langsmith could expose Openai keys and user data via malicious agents

June 17, 2025

Silver Fox Apt targets Taiwan with complex GH0stringe and HoldingHands rat malware

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Senate passes landmark genius law stablecoin bill

Florida State Legislatures Pass Charter School Expansion

OpenAI’s AI Technology to Revolutionize Military Operations?

Google Chrome Zero-Day CVE-2025-2783 Taxoff exploits Trinper Backdoor

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

OpenAI’s AI Technology to Revolutionize Military Operations?

Elon Musk’s AI startup Xai raises $4.3 billion in equity funding in addition to $5 billion in debt transactions during the surge in AI costs

Sword Health lands $40 million to expand AI care into mental health, valuing $4 billion

R0AR introduces a unified defi platform for tokens, liquidity and NFT staking

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.