s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.flodrix

📛 Threat Title

Malware family: Flodrix

Category: Flodrix First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.flodrix`. Printable name: Flodrix.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.flodrix VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.flodrix

IOC database

Type
domain
Value
elf.flodrix
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.flodrix

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.flodrix

References (1)

Remediations (10)

  • web:blog.polyswarm.io

    The malware employs stealth techniques, including self-deletion and string obfuscation, to evade detection. CVE-2025-3248 Exploitation An active campaign exploiting a severe flaw in Langflow, a Python-based framework for building AI applications, has been uncovered, delivering the Flodrix botnet to vulnerable servers.

  • web:cyberpress.org

    Persistence: Flodrix uses XOR-based decryption (key: qE6MGAbI) to hide C&C IPs, establishes TCP/UDP channels, and terminates competing processes like busybox or watchdog. The botnet supports six DDoS attack modes, including tcpraw udpplain, while evading detection through self-deletion and artifact removal. Mitigation Strategies and Patch Analysis

  • web:cybersecuritynews.com

    Langflow hit by CVE-2025-3248 flaw letting attackers run Python code via POST. Exploited fast, linking to new Flodrix botnet malware .

  • web:cybersecuritynews.com

    The Flodrix botnet represents an evolution of the LeetHozer malware family , incorporating advanced stealth techniques, including self-deletion and artifact removal, to evade detection. The malware employs string obfuscation using XOR encryption with the key "qE6MGAbI" to conceal command-and-control server addresses.

  • web:gbhackers.com

    Flodrix also checks for hidden files to avoid reinfecting the same host and forks child processes with fake names to evade detection. Flodrix is a sophisticated descendant of the LeetHozer malware family , but with enhanced stealth and attack features. It can: Launch multiple types of DDoS attacks (e.g., tcpraw, udpplain, handshake, tcplegit ...

  • web:securityonline.info

    A critical RCE flaw (CVE-2025-3248) in Langflow is being actively exploited to deploy the stealthy Flodrix botnet for reconnaissance and diverse DDoS attacks on AI app servers.

  • web:thehackernews.com

    Cybersecurity researchers have called attention to a new campaign that's actively exploiting a recently disclosed critical security flaw in Langflow to deliver the Flodrix botnet malware . "Attackers use the vulnerability to execute downloader scripts on compromised Langflow servers, which in turn ...

  • web:undercodenews.com

    Once identified, they use publicly available PoC (proof-of-concept) exploits to gain shell access, perform reconnaissance, and deploy a shell script named "docker" that pulls and executes ELF binaries of the Flodrix botnet. The malware is capable of executing TCP-based DDoS attacks and is adaptable to multiple system architectures.

  • web:www.darkreading.com

    Hackers Exploit Critical Langflow Flaw to Unleash Flodrix Botnet A vulnerability in the popular Python-based tool for building AI agents and workflows is under active exploitation, allowing for ...

  • web:www.trendmicro.com

    Trend™ Research has identified an active campaign exploiting CVE-2025-3248 to deliver the Flodrix botnet. Attackers use the vulnerability to execute downloader scripts on compromised Langflow servers, which in turn fetch and install the Flodrix malware . CVE-2025-3248 (CVSS 9.8) is a critical vulnerability in Langflow versions before 1.3.0.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.