s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.shadowv2

📛 Threat Title

Malware family: ShadowV2

Category: ShadowV2 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.shadowv2`. Printable name: ShadowV2.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cyberpress.org

    ShadowV2 botnet - ShadowV2 represents a new breed of cybercrime-as-a-service, combining traditional malware techniques with cloud.

  • web:cybersecsentinel.com

    Threat Group - ShadowV2 operators cybercrime as a service actors Threat Type - DDoS as a Service and botnet Exploited Vulnerabilities - Publicly exposed or unauthenticated Docker daemon APIs on cloud hosts, weak network segmentation, deficient egress controls, inadequate governance of infrastructure as code Malware Used - Python based spreader and control scripts, Go

  • web:cybersecuritynews.com

    During late October 2025, a new malware campaign dubbed ShadowV2 emerged, coinciding with a global AWS disruption. This sophisticated threat actively exploits vulnerabilities in IoT devices to assemble a botnet for distributed denial-of-service (DDoS) attacks.

  • web:gbhackers.com

    ShadowV2 is assessed to be a derivative of the notorious Mirai botnet architecture, explicitly re-engineered for IoT environments. During execution, the malware displays the string " ShadowV2 Build v1.0.0 IoT version," suggesting this is the initial release targeting these specific devices. Display string while executing ShadowV2 .

  • web:securityaffairs.com

    ShadowV2 , a new Mirai-based botnet, briefly targeted vulnerable IoT devices during October's AWS outage, likely as a test run. During the late-October AWS disruption, FortiGuard Labs researchers observed the Mirai -based 'ShadowV2' malware exploiting IoT vulnerabilities across multiple countries and industries.

  • web:thehackernews.com

    The ShadowV2 botnet, according to Darktrace, predominantly targets misconfigured Docker containers on Amazon Web Services (AWS) cloud servers to deploy a Go-based malware that turns infected systems into attack nodes and co-opt them into a larger DDoS botnet.

  • web:www.bleepingcomputer.com

    A new Mirai-based botnet malware named 'ShadowV2' has been observed targeting IoT devices from D-Link, TP-Link, and other vendors with exploits for known vulnerabilities.

  • web:www.broadcom.com

    FortiGuard Labs recently reported on ShadowV2 , a Mirai-based malware , targeting IoT devices during the large-scale AWS disruption incident in October. Exploiting vulnerabilities across various vendor products, the malware utilizes a downloader script to establish C2 communication and executes multi-vector DDoS flood attacks (TCP, UDP, and HTTP).

  • web:www.fortinet.com

    ShadowV2 , a new Mirai-based botnet targeting IoT devices, surfaced during the recent AWS outage. FortiGuard Labs examines its propagation, DDoS capabilities, and global footprint.

  • web:www.techworm.net

    Security researchers at Fortinet's FortiGuard Labs have identified a new Mirai-based botnet called ShadowV2 that quietly emerged during the major AWS outage in October, targeting vulnerable IoT devices worldwide and disappearing soon after the outage ended.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.