Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger

Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger

Posted on June 26, 2025June 26, 2025 By CWS

The Androxgh0st botnet has considerably expanded its operations since 2023, with cybercriminals now compromising prestigious tutorial establishments to host their command and management infrastructure.

This refined malware marketing campaign has demonstrated outstanding persistence and evolution, focusing on a various vary of vulnerabilities throughout net functions, frameworks, and Web of Issues units to ascertain widespread community entry.

The botnet’s operators have proven specific crafty of their collection of internet hosting infrastructure, preferring to embed their malicious operations inside authentic, trusted domains.

This strategic strategy not solely supplies operational cowl but in addition exploits the inherent belief related to instructional and institutional web sites.

The selection to focus on tutorial establishments displays a calculated choice to leverage domains that usually obtain much less scrutiny from safety monitoring methods and preserve excessive popularity scores with safety distributors.

CloudSEK analysts recognized that the Androxgh0st operators efficiently compromised a College of California, San Diego subdomain, particularly “api.usarhythms.ucsd.edu,” to host their command and management logger.

Attempting to find malicious infrastructure – discovered misconfigured Logger and Command Sender panels (Supply – Cloudsek)

This specific subdomain seems to be related to the USA Basketball Males’s U19 Nationwide Staff portal, demonstrating how attackers exploit authentic however doubtlessly under-monitored institutional net properties.

The compromise represents a big escalation within the botnet’s sophistication and operational safety measures.

The malware’s assault methodology encompasses exploitation of over twenty distinct vulnerabilities, marking a fifty p.c improve in preliminary entry vectors in comparison with earlier campaigns.

These vulnerabilities span a number of expertise stacks together with Apache Shiro JNDI injection flaws, Spring Framework distant code execution vulnerabilities (Spring4Shell), WordPress plugin weaknesses, and Web of Issues system command injection vulnerabilities.

The variety of assault vectors ensures broad goal protection and maximizes the probability of profitable system compromise throughout completely different organizational environments.

Webshell Deployment and Persistence Mechanisms

The Androxgh0st operators deploy a classy arsenal of 4 distinct webshells designed for persistent entry and continued exploitation of compromised methods.

The first webshell, “abuok.php,” employs hexadecimal encoding mixed with PHP’s eval operate to execute obfuscated payloads.

The malicious code makes use of eval(hex2bin()) to decode and execute embedded instructions, whereas wrapping the payload in seemingly innocuous textual content strings to evade fundamental detection mechanisms.

error_reporting(0); eval(hex2bin(“636c617373204e7b707…”));

The “myabu.php” variant demonstrates further evasion strategies by ROT13 encoding, the place str_rot13(“riny”) produces “eval” to execute arbitrary code submitted by way of POST requests.

This encoding technique supplies a easy but efficient obfuscation layer that bypasses signature-based detection methods whereas sustaining full distant code execution capabilities.

The webshells collectively allow file add performance, code injection capabilities, and protracted backdoor entry, making certain that even when major an infection vectors are patched, the attackers preserve a number of pathways for continued system entry and exploitation.

Examine dwell malware conduct, hint each step of an assault, and make quicker, smarter safety choices -> Attempt ANY.RUN now

Cyber Security News Tags:Androxgh0st, Botnet, Exploiting, Hosting, Logger, Operators, University

Post navigation

Previous Post: British Man Suspected of Being the Hacker IntelBroker Arrested, Charged
Next Post: Iranian APT35 Hackers Targeting Israeli Tech Experts with AI-Powered Phishing Attacks

Related Posts

Banana RAT Targets Brazilian Financial Sector with NF-e Lures Banana RAT Targets Brazilian Financial Sector with NF-e Lures Cyber Security News
Lessons from Oracle E-Business Suite Hack That Allegedly Compromises Nearly 30 Organizations Worldwide Lessons from Oracle E-Business Suite Hack That Allegedly Compromises Nearly 30 Organizations Worldwide Cyber Security News
LinkedIn Social Engineering Targets Cryptocurrency Firms LinkedIn Social Engineering Targets Cryptocurrency Firms Cyber Security News
100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild 100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild Cyber Security News
An Open-Source Tool to See Through Encrypted Traffic in Linux systems An Open-Source Tool to See Through Encrypted Traffic in Linux systems Cyber Security News
BreachLock Named Representative Provider for Penetration Testing as a Service (PTaaS) in New Gartner® Report BreachLock Named Representative Provider for Penetration Testing as a Service (PTaaS) in New Gartner® Report Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark