{"id":4916,"date":"2025-06-26T10:05:35","date_gmt":"2025-06-26T10:05:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/26\/androxgh0st-botnet-operators-exploiting-us-university-for-hosting-c2-logger\/"},"modified":"2025-06-26T10:05:35","modified_gmt":"2025-06-26T10:05:35","slug":"androxgh0st-botnet-operators-exploiting-us-university-for-hosting-c2-logger","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/26\/androxgh0st-botnet-operators-exploiting-us-university-for-hosting-c2-logger\/","title":{"rendered":"Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger"},"content":{"rendered":"<p>    Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Androxgh0st botnet has significantly expanded its operations since 2023, with cybercriminals now compromising prestigious academic institutions to host their command and control infrastructure.<\/p>\n<p>This sophisticated malware campaign has demonstrated remarkable persistence and evolution, targeting a diverse range of vulnerabilities across web applications, frameworks, and Internet of Things devices to establish widespread network access.<\/p>\n<p>The botnet\u2019s operators have shown particular cunning in their selection of hosting infrastructure, preferring to embed their malicious operations within legitimate, trusted domains.<\/p>\n<p>This strategic approach not only provides operational cover but also exploits the inherent trust associated with educational and institutional websites.<\/p>\n<p>The choice to target academic institutions reflects a calculated decision to leverage domains that typically receive less scrutiny from security monitoring systems and maintain high reputation scores with security vendors.<\/p>\n<p>CloudSEK analysts <a href=\"https:\/\/www.cloudsek.com\/blog\/androxgh0st-continues-exploitation-operators-compromise-a-us-university-for-hosting-c2-logger\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that the Androxgh0st operators successfully compromised a University of California, San Diego subdomain, specifically \u201capi.usarhythms.ucsd.edu,\u201d to host their command and control logger.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKsgdcf3p1A1VM8HKp14eNkOCGTNWjy3d306vY-7tGDGyBI5jmMsMF2iGmA1Vt4Lr1Ze_jsSzXWa-o1_1VO0X6HKyOvNln1d0l3t_SluRRZvXrv8fUx5KibeIDiWn_NAHqOWH8FQIRjdyt9v8zVp6FYXPFLVCEKA_LHkuWFiGFRVTgQAwZnX62oA1U96Q\/s16000\/Hunting%2520for%2520malicious%2520infrastructure%2520-%2520found%2520misconfigured%2520Logger%2520and%2520Command%2520Sender%2520panels%2520%28Source%2520-%2520Cloudsek%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Hunting for malicious infrastructure \u2013 found misconfigured Logger and Command Sender panels (Source \u2013 Cloudsek)<\/figcaption><\/figure>\n<\/div>\n<p>This particular subdomain appears to be associated with the USA Basketball Men\u2019s U19 National Team portal, demonstrating how attackers exploit legitimate but potentially under-monitored institutional web properties.<\/p>\n<p>The compromise represents a significant escalation in the botnet\u2019s sophistication and operational <a href=\"https:\/\/cybersecuritynews.com\/ipv6-security-best-practices-recommended-security-measures\/\" target=\"_blank\" rel=\"noreferrer noopener\">security measures<\/a>.<\/p>\n<p>The malware\u2019s attack methodology encompasses exploitation of over twenty distinct vulnerabilities, marking a fifty percent increase in initial access vectors compared to previous campaigns.<\/p>\n<p>These vulnerabilities span multiple technology stacks including Apache Shiro JNDI injection flaws, Spring Framework remote code execution vulnerabilities (Spring4Shell), WordPress plugin weaknesses, and Internet of Things device command injection vulnerabilities.<\/p>\n<p>The diversity of <a href=\"https:\/\/cybersecuritynews.com\/process-hollowing-attack-windows-11\/\" target=\"_blank\" rel=\"noreferrer noopener\">attack vectors<\/a> ensures broad target coverage and maximizes the likelihood of successful system compromise across different organizational environments.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Webshell Deployment and Persistence Mechanisms<\/strong><\/h2>\n<p>The Androxgh0st operators deploy a sophisticated arsenal of four distinct webshells designed for persistent access and continued exploitation of compromised systems.<\/p>\n<p>The primary webshell, \u201cabuok.php,\u201d employs hexadecimal encoding combined with PHP\u2019s eval function to execute obfuscated payloads.<\/p>\n<p>The malicious code utilizes <code>eval(hex2bin())<\/code> to decode and execute embedded commands, while wrapping the payload in seemingly innocuous text strings to evade basic detection mechanisms.<\/p>\n<pre class=\"wp-block-code\"><code>error_reporting(0); eval(hex2bin(\"636c617373204e7b707...\"));<\/code><\/pre>\n<p>The \u201cmyabu.php\u201d variant demonstrates additional evasion techniques through ROT13 encoding, where <code>str_rot13(\"riny\")<\/code> produces \u201ceval\u201d to execute arbitrary code submitted via POST requests.<\/p>\n<p>This encoding method provides a simple yet effective obfuscation layer that bypasses signature-based detection systems while maintaining full <a href=\"https:\/\/cybersecuritynews.com\/windows-remote-desktop-services-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">remote code execution<\/a> capabilities.<\/p>\n<p>The webshells collectively enable file upload functionality, code injection capabilities, and persistent backdoor access, ensuring that even if primary infection vectors are patched, the attackers maintain multiple pathways for continued system access and exploitation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/androxgh0st-botnet-operators-exploiting-us-university\/\">Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/androxgh0st-botnet-operators-exploiting-us-university\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger The Androxgh0st botnet has significantly expanded its operations since 2023, with cybercriminals now compromising prestigious academic institutions to host their command and control infrastructure. This sophisticated malware campaign has demonstrated remarkable persistence and evolution, targeting a diverse range of vulnerabilities across web applications, frameworks, and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4916","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4916"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4916"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4916\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4916"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4916"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}