TF-MAL-elf.flodrix
📛 Threat Title
Malware family: Flodrix
Description
ThreatFox malware family `elf.flodrix`. Printable name: Flodrix.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.flodrix
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.flodrix
IOC database
- Type
- domain
- Value
elf.flodrix- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.flodrix
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.flodrix
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.polyswarm.io
The malware employs stealth techniques, including self-deletion and string obfuscation, to evade detection. CVE-2025-3248 Exploitation An active campaign exploiting a severe flaw in Langflow, a Python-based framework for building AI applications, has been uncovered, delivering the Flodrix botnet to vulnerable servers.
-
web:cyberpress.org
Persistence: Flodrix uses XOR-based decryption (key: qE6MGAbI) to hide C&C IPs, establishes TCP/UDP channels, and terminates competing processes like busybox or watchdog. The botnet supports six DDoS attack modes, including tcpraw udpplain, while evading detection through self-deletion and artifact removal. Mitigation Strategies and Patch Analysis
-
web:cybersecuritynews.com
Langflow hit by CVE-2025-3248 flaw letting attackers run Python code via POST. Exploited fast, linking to new Flodrix botnet malware .
-
web:cybersecuritynews.com
The Flodrix botnet represents an evolution of the LeetHozer malware family , incorporating advanced stealth techniques, including self-deletion and artifact removal, to evade detection. The malware employs string obfuscation using XOR encryption with the key "qE6MGAbI" to conceal command-and-control server addresses.
-
web:gbhackers.com
Flodrix also checks for hidden files to avoid reinfecting the same host and forks child processes with fake names to evade detection. Flodrix is a sophisticated descendant of the LeetHozer malware family , but with enhanced stealth and attack features. It can: Launch multiple types of DDoS attacks (e.g., tcpraw, udpplain, handshake, tcplegit ...
-
web:securityonline.info
A critical RCE flaw (CVE-2025-3248) in Langflow is being actively exploited to deploy the stealthy Flodrix botnet for reconnaissance and diverse DDoS attacks on AI app servers.
-
web:thehackernews.com
Cybersecurity researchers have called attention to a new campaign that's actively exploiting a recently disclosed critical security flaw in Langflow to deliver the Flodrix botnet malware . "Attackers use the vulnerability to execute downloader scripts on compromised Langflow servers, which in turn ...
-
web:undercodenews.com
Once identified, they use publicly available PoC (proof-of-concept) exploits to gain shell access, perform reconnaissance, and deploy a shell script named "docker" that pulls and executes ELF binaries of the Flodrix botnet. The malware is capable of executing TCP-based DDoS attacks and is adaptable to multiple system architectures.
-
web:www.darkreading.com
Hackers Exploit Critical Langflow Flaw to Unleash Flodrix Botnet A vulnerability in the popular Python-based tool for building AI agents and workflows is under active exploitation, allowing for ...
-
web:www.trendmicro.com
Trend™ Research has identified an active campaign exploiting CVE-2025-3248 to deliver the Flodrix botnet. Attackers use the vulnerability to execute downloader scripts on compromised Langflow servers, which in turn fetch and install the Flodrix malware . CVE-2025-3248 (CVSS 9.8) is a critical vulnerability in Langflow versions before 1.3.0.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.