SYMBOLCOMMON_NAMEaka. SYNONYMS
elf.bashlite (Back to overview)

Bashlite

aka: gayfgt, Gafgyt, qbot, torlus, lizkebab
VTCollection     URLhaus        

Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.

References
2026-06-03 ⋅ Fortinet ⋅ Vincent Li
Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO
Bashlite C0XMO
2024-08-14 ⋅ Aquasec ⋅ Assaf Morag
Gafgyt Malware Variant Exploits GPU Power and Cloud Native Environments
Bashlite
2024-07-09 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update January to June 2024
Coper FluBot Hook Bashlite Mirai FAKEUPDATES AsyncRAT BianLian Cobalt Strike DCRat Havoc NjRAT QakBot Quasar RAT RedLine Stealer Remcos Rhadamanthys RisePro Sliver
2024-04-07 ⋅ cyber5w ⋅ M4lcode
Gafgyt Backdoor Analysis
Bashlite
2022-11-02 ⋅ NOZOMI Network Labs ⋅ Nozomi Networks Labs
Could Threat Actors Be Downgrading Their Malware to Evade Detection?
Bashlite
2022-10-17 ⋅ SecurityScorecard ⋅ Vlad Pasca
A Detailed Analysis of the Gafgyt Malware Targeting IoT Devices
Bashlite
2022-05-20 ⋅ Palo Alto Networks Unit 42 ⋅ Ruchna Nigam
Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
Bashlite Mirai PerlBot
2022-04-19 ⋅ 360 ⋅ 360 Netlab
Public Cloud Cybersecurity Threat Intelligence (202203)
Bashlite Tsunami Mirai
2022-02-25 ⋅ 360 netlab ⋅ Ghost
Some details of the DDoS attacks targeting Ukraine and Russia in recent days
Bashlite Mirai MooBot PerlBot
2022-02-25 ⋅ ⋅ 360 netlab ⋅ Ghost
Details of the DDoS attacks we have seen recently against Ukraine and Russia
Bashlite Mirai Mirai
2021-10-27 ⋅ AT&T ⋅ Fernando Dominguez
Code similarity analysis with r2diaphora
Bashlite
2021-09-07 ⋅ CUJOAI ⋅ Albert Zsigovits
Threat Alert: Mirai/Gafgyt Fork with New DDoS Modules Discovered
Bashlite Mirai
2021-05-17 ⋅ Uptycs ⋅ Ashwin Vamshi, Siddartha Sharma
Discovery of Simps Botnet Leads To Ties to Keksec Group
Bashlite Mirai
2021-04-15 ⋅ Uptycs ⋅ Siddharth Sharma
Mirai code re-use in Gafgyt
Bashlite Mirai
2021-03-21 ⋅ Blackberry ⋅ Blackberry Research
2021 Threat Report
Bashlite FritzFrog IPStorm Mirai Tsunami elf.wellmess AppleJeus Dacls EvilQuest Manuscrypt Astaroth BazarBackdoor Cerber Cobalt Strike Emotet FinFisher RAT Kwampirs MimiKatz NjRAT Ryuk SmokeLoader TrickBot
2021-03-04 ⋅ 360 netlab ⋅ Jinye
Gafgtyt_tor and Necro are on the move again
Bashlite N3Cr0m0rPh Keksec
2020-12-07 ⋅ Avira ⋅ Avira Protection Labs
A Gafgyt variant that exploits Pulse Secure CVE-2020-8218
Bashlite
2020-09-30 ⋅ Qihoo 360 Technology ⋅ Ya Liu
Lightweight Emulation based IOC Extraction for Gafgyt Botnets
Bashlite
2020-07-06 ⋅ 360 netlab ⋅ Ya Liu
The Gafgyt variant vbot seen in its 31 campaigns
Bashlite
2020-05-14 ⋅ paloalto Networks Unit 42 ⋅ Ruchna Nigam
Mirai and Hoaxcalls Botnets Target Legacy Symantec Web Gateways
Bashlite Mirai
2020-04-03 ⋅ Palo Alto Networks Unit 42 ⋅ Haozhe Zhang, Ken Hsu, Ruchna Nigam, Zhibin Zhang
Grandstream and DrayTek Devices Exploited to Power New Hoaxcalls DDoS Botnet
Bashlite
2019-10-14 ⋅ Max Kersten's Blog ⋅ Max Kersten
Corona DDoS bot
Bashlite
2018-09-09 ⋅ Palo Alto Networks Unit 42 ⋅ Ruchna Nigam
Multi-exploit IoT/Linux Botnets Mirai and Gafgyt Target Apache Struts, SonicWall
Bashlite Mirai
2016-09-21 ⋅ Brian Krebs
KrebsOnSecurity Hit With Record DDoS
Bashlite
2015-09-01 ⋅ Virus Bulletin ⋅ Jaromír Hořejší, Peter Kálnai
DDOS TROJAN: A MALICIOUS CONCEPT THAT CONQUERED THE ELF FORMAT
Bashlite MrBlack XOR DDoS BillGates
2014-11-13 ⋅ Trend Micro ⋅ Rhena Inocencio
BASHLITE Affects Devices Running on BusyBox
Bashlite
Yara Rules
[TLP:WHITE] elf_bashlite_auto (20260917 | Detects elf.bashlite.)
rule elf_bashlite_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects elf.bashlite."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { eb0a c785ecefffff00000000 8b85ecefffff c9 c3 }
            // n = 5, score = 300
            //   eb0a                 | js                  0x55
            //   c785ecefffff00000000     | and    word ptr [ebp], 0x2000
            //   8b85ecefffff         | test                eax, eax
            //   c9                   | mov                 ecx, eax
            //   c3                   | js                  0x15b

        $sequence_1 = { 750c c785ecefffff01000000 eb0a c785ecefffff00000000 8b85ecefffff c9 c3 }
            // n = 7, score = 300
            //   750c                 | dec                 esp
            //   c785ecefffff01000000     | mov    edx, eax
            //   eb0a                 | jmp                 0x7df
            //   c785ecefffff00000000     | dec    esp
            //   8b85ecefffff         | cmp                 eax, ecx
            //   c9                   | dec                 ecx
            //   c3                   | cmovae              eax, eax

        $sequence_2 = { 31c0 eb19 e8???????? c70016000000 e8???????? c70016000000 83c8ff }
            // n = 7, score = 300
            //   31c0                 | cmp                 dword ptr [ebp - 0x11c], 1
            //   eb19                 | je                  0x3a6
            //   e8????????           |                     
            //   c70016000000         | cmp                 dword ptr [ebp - 0x11c], 2
            //   e8????????           |                     
            //   c70016000000         | je                  0x508
            //   83c8ff               | movzx               eax, byte ptr [edx + eax*8 + 4]

        $sequence_3 = { e8???????? 89c2 89d0 c1e81f 01d0 d1f8 }
            // n = 6, score = 300
            //   e8????????           |                     
            //   89c2                 | dec                 eax
            //   89d0                 | mov                 edi, ebx
            //   c1e81f               | dec                 eax
            //   01d0                 | lea                 esi, [ebp - 0x221]
            //   d1f8                 | mov                 edi, dword ptr [ebp - 0x20]

        $sequence_4 = { c785ecefffff01000000 eb0a c785ecefffff00000000 8b85ecefffff }
            // n = 4, score = 300
            //   c785ecefffff01000000     | mov    eax, dword ptr [ebp - 0x38]
            //   eb0a                 | mov                 dword ptr [ebp - 0x3c], eax
            //   c785ecefffff00000000     | dec    eax
            //   8b85ecefffff         | mov                 eax, dword ptr [ebp - 0x20]

        $sequence_5 = { 750c c785ecefffff01000000 eb0a c785ecefffff00000000 8b85ecefffff }
            // n = 5, score = 300
            //   750c                 | lea                 eax, [edi + ebp]
            //   c785ecefffff01000000     | cmp    esi, eax
            //   eb0a                 | je                  0x364
            //   c785ecefffff00000000     | dec    eax
            //   8b85ecefffff         | inc                 eax

        $sequence_6 = { 89c2 89d0 c1e81f 01d0 }
            // n = 4, score = 300
            //   89c2                 | mov                 eax, dword ptr [ebp - 0x38]
            //   89d0                 | mov                 al, byte ptr [eax]
            //   c1e81f               | cmp                 al, 0x21
            //   01d0                 | mov                 dword ptr [ebp - 0x38], eax

        $sequence_7 = { 750c c785ecefffff01000000 eb0a c785ecefffff00000000 }
            // n = 4, score = 300
            //   750c                 | mov                 word ptr [ebp - 0x1e], ax
            //   c785ecefffff01000000     | mov    word ptr [ebp - 0x20], 2
            //   eb0a                 | mov                 edx, 6
            //   c785ecefffff00000000     | mov    esi, 1

        $sequence_8 = { 83f8ff 750c e8???????? 8b00 83f873 }
            // n = 5, score = 300
            //   83f8ff               | sub                 esp, 0xc
            //   750c                 | push                eax
            //   e8????????           |                     
            //   8b00                 | add                 esp, 0x10
            //   83f873               | and                 eax, dword ptr [ebp + 8]

        $sequence_9 = { eb19 e8???????? c70016000000 e8???????? c70016000000 83c8ff }
            // n = 6, score = 300
            //   eb19                 | mov                 eax, dword ptr [ebp - 0x30]
            //   e8????????           |                     
            //   c70016000000         | dec                 eax
            //   e8????????           |                     
            //   c70016000000         | mov                 edx, dword ptr [ebp - 0x40]
            //   83c8ff               | dec                 eax

    condition:
        7 of them and filesize < 2310144
}
Download all Yara Rules