{"id":2476,"date":"2021-04-19T21:09:16","date_gmt":"2021-04-20T02:09:16","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2476"},"modified":"2021-04-19T21:09:46","modified_gmt":"2021-04-20T02:09:46","slug":"gafgyt-is-a-botnet-that-uses-mirai-ddos-modules","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/","title":{"rendered":"Gafgyt is a botnet that uses Mirai DDoS modules"},"content":{"rendered":"\n<p>First discovered in 2014, Gafgyt (also known as Bashlite) generally targets vulnerable IoT devices such as Huawei routers, Realtek routers, and ASUS devices, and in turn also uses exploits to hack and access computers. According to the researchers, the Gafgyt malware variants have a very similar functionality to Mirai, since most of the code was copied.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Features of the Gafgyt botnet<\/h2>\n\n\n\n<p>Meanwhile, the latest versions of Gafgyt contain new approaches to achieving the initial engagement of IoT devices, Uptycs discovered; This is the first step in turning infected devices into bots and then DDoS attacks on specific IP addresses. These include a module copied from Mirai for Telnet brute force and additional exploits for existing vulnerabilities on Huawei, Realtek and GPON devices.<\/p>\n\n\n\n<p>Recent versions of Gafgyt also incorporate a brute-force telnet scanner, copied from Mirai, as well as the GPON exploit (CVE-2018-10561), which is used to bypass authentication on vulnerable Dasan GPON routers.<\/p>\n\n\n\n<p>IoT botnets like Gafgyt are constantly evolving. For example, researchers in March discovered what they said is the first variant of the Gafgyt botnet family that hides its activity using the Tor network and thus botnets are a threat that should not be ignored.<\/p>\n\n\n\n<p>Malware authors may not always innovate, and researchers often find that malware authors copy and reuse leaked malware source code, \u201dUptycs said. To prevent such attacks, users should regularly monitor suspicious processes, events, and network traffic generated by running any untrusted binaries, and keep systems and firmware up-to-date with the latest versions and patches remember that you can never be prepared enough.<\/p>\n\n\n\n<p>Check also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/ddos-attacks-increased-350-after-lockdown\/\">DDoS attacks increased 350% after lockdown<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/what-are-the-most-common-ddos-attacks\/\">What are the most common DDoS attacks<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/freakout-a-botnet-targeting-linux\/\">FreakOut \u2013 A Botnet targeting Linux<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/ipstorm-what-we-know-about-this-botnet\/\">IPStorm \u2013 What we know about this botnet<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>First discovered in 2014, Gafgyt (also known as Bashlite) generally targets vulnerable IoT devices such as Huawei routers, Realtek routers, and ASUS devices, and in turn also uses exploits to hack and access computers. According to the researchers, the Gafgyt malware variants have a very similar functionality to Mirai, since most of the code was [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2477,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2476","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Gafgyt is a botnet that uses Mirai DDoS modules - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Gafgyt is a botnet that has been active lately due to its updates and we will see how it worked and where it came from.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Gafgyt is a botnet that uses Mirai DDoS modules - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Gafgyt is a botnet that has been active lately due to its updates and we will see how it worked and where it came from.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-20T02:09:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-20T02:09:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/botnet.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2000\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Gafgyt is a botnet that uses Mirai DDoS modules\",\"datePublished\":\"2021-04-20T02:09:16+00:00\",\"dateModified\":\"2021-04-20T02:09:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/\"},\"wordCount\":294,\"commentCount\":3,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/botnet.png\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/\",\"name\":\"Gafgyt is a botnet that uses Mirai DDoS modules - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/botnet.png\",\"datePublished\":\"2021-04-20T02:09:16+00:00\",\"dateModified\":\"2021-04-20T02:09:46+00:00\",\"description\":\"Gafgyt is a botnet that has been active lately due to its updates and we will see how it worked and where it came from.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/botnet.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/botnet.png\",\"width\":2000,\"height\":1000},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Gafgyt is a botnet that uses Mirai DDoS modules\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Gafgyt is a botnet that uses Mirai DDoS modules - Truxgo Server Blog","description":"Gafgyt is a botnet that has been active lately due to its updates and we will see how it worked and where it came from.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/","og_locale":"es_MX","og_type":"article","og_title":"Gafgyt is a botnet that uses Mirai DDoS modules - Truxgo Server Blog","og_description":"Gafgyt is a botnet that has been active lately due to its updates and we will see how it worked and where it came from.....","og_url":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-04-20T02:09:16+00:00","article_modified_time":"2021-04-20T02:09:46+00:00","og_image":[{"width":2000,"height":1000,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/botnet.png","type":"image\/png"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Gafgyt is a botnet that uses Mirai DDoS modules","datePublished":"2021-04-20T02:09:16+00:00","dateModified":"2021-04-20T02:09:46+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/"},"wordCount":294,"commentCount":3,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/botnet.png","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/","url":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/","name":"Gafgyt is a botnet that uses Mirai DDoS modules - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/botnet.png","datePublished":"2021-04-20T02:09:16+00:00","dateModified":"2021-04-20T02:09:46+00:00","description":"Gafgyt is a botnet that has been active lately due to its updates and we will see how it worked and where it came from.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/botnet.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/botnet.png","width":2000,"height":1000},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/gafgyt-is-a-botnet-that-uses-mirai-ddos-modules\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Gafgyt is a botnet that uses Mirai DDoS modules"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2476"}],"version-history":[{"count":5,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2476\/revisions"}],"predecessor-version":[{"id":4215,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2476\/revisions\/4215"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2477"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2476"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2476"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}