Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Benchmark for Greptile’s Lead Series A lecture, AI Code Reviewer, valued at $100 million, according to sources

Why Y Combinator Startups Working on Windows AI Agents and Get Pivoted

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » New flodrix botnet variant exploits langflow ai server rce bug to launch DDOS attacks
Identity

New flodrix botnet variant exploits langflow ai server rce bug to launch DDOS attacks

userBy userJune 17, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 17, 2025Ravi LakshmananBotnet/Vulnerability

New flodrix botnet variant

Cybersecurity researchers have called attention to a new campaign that will actively leverage the critical security flaws recently disclosed on Langflow to provide Flodrix BotNet malware.

“Attackers use the vulnerability to run downloader scripts on the compromised Langflow server to retrieve and install Flodrix malware,” Trend Micro researchers Aliakbar Zahravi, Ahmed Mohamed Ibrahim, Sunil Bharti and Shubham Singh said in a technical report released today.

This activity involves exploitation of CVE-2025-3248 (CVSS score: 9.8). This lacks the authentication vulnerability in Langflow, a Python-based “visual framework” for building artificial intelligence (AI) applications.

Cybersecurity

The successful exploitation of the flaws allows uncertified attackers to execute arbitrary code via created HTTP requests. Patched by Langflow in version 1.3.0 in March 2025.

Last month, the US Cybersecurity and Infrastructure Security Agency (CISA) flagged the aggressive exploitation of CVE-2025-3248 in the wild, and the SANS Technology Institute revealed it had detected attempts to exploit against honeypot servers.

The latest findings from Trend Micro show that threat actors are conducting reconnaissance to leverage published proof of concept (POC) code and “targeting unearned internet exposed Langflow instances that leverage public proof of concept (POC) code to drop shell script downloaders responsible for obtaining and running Frodricksbotnet malware from 80.66.75.”[.]121:25565. ”

Once installed, FLODRIX configures communication with a remote server that receives commands over TCP to invoke a distributed deny (DDOS) attack on the target target IP address. The botnet also supports connections over the Tor Anonymous Network.

“LangFlow does not force input validation or sandboxes, so these payloads are compiled and executed within the context of the server. [remote code execution]”Based on these steps, attackers are likely to be profiled all vulnerable servers, using the data collected to identify high-value targets for future infections.”

Trend Micro identified unknown threat actors hosting different download device scripts on the same host used to fetch Flodrix, suggesting that the campaign is doing aggressive development.

Cybersecurity

Flodrix is ​​rated as an evolution of another botnet called Leethozer, linked to the Moobot group. The improved variant incorporates the ability to carefully remove command and control (C2) server addresses and other important metrics, minimizing forensic traces and complicating analytical efforts.

“Another important change is the introduction of a new DDOS attack type, which is now encrypted and has added a layer of observation,” Trend Micro said. “The new sample enumerates the running processes by opening the /Proc directory to access all running processes.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOuternet London cracks live audience measurement codes
Next Article Over a third of UK companies are not dangerously prepared for AI risks
user
  • Website

Related Posts

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

July 18, 2025

China’s vast tools secretly extract from SMS, GPS data and confiscated mobile phones.

July 18, 2025

UNG0002 group hits Hong Kong China in Pakistan using LNK files and rats in twin campaign

July 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Benchmark for Greptile’s Lead Series A lecture, AI Code Reviewer, valued at $100 million, according to sources

Why Y Combinator Startups Working on Windows AI Agents and Get Pivoted

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

Cursor snaps up enterprise startup koala with a challenge to github copilot

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.