TF-MAL-elf.shadowv2
📛 Threat Title
Malware family: ShadowV2
Description
ThreatFox malware family `elf.shadowv2`. Printable name: ShadowV2.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
ShadowV2 botnet - ShadowV2 represents a new breed of cybercrime-as-a-service, combining traditional malware techniques with cloud.
-
web:cybersecsentinel.com
Threat Group - ShadowV2 operators cybercrime as a service actors Threat Type - DDoS as a Service and botnet Exploited Vulnerabilities - Publicly exposed or unauthenticated Docker daemon APIs on cloud hosts, weak network segmentation, deficient egress controls, inadequate governance of infrastructure as code Malware Used - Python based spreader and control scripts, Go
-
web:cybersecuritynews.com
During late October 2025, a new malware campaign dubbed ShadowV2 emerged, coinciding with a global AWS disruption. This sophisticated threat actively exploits vulnerabilities in IoT devices to assemble a botnet for distributed denial-of-service (DDoS) attacks.
-
web:gbhackers.com
ShadowV2 is assessed to be a derivative of the notorious Mirai botnet architecture, explicitly re-engineered for IoT environments. During execution, the malware displays the string " ShadowV2 Build v1.0.0 IoT version," suggesting this is the initial release targeting these specific devices. Display string while executing ShadowV2 .
-
web:securityaffairs.com
ShadowV2 , a new Mirai-based botnet, briefly targeted vulnerable IoT devices during October's AWS outage, likely as a test run. During the late-October AWS disruption, FortiGuard Labs researchers observed the Mirai -based 'ShadowV2' malware exploiting IoT vulnerabilities across multiple countries and industries.
-
web:thehackernews.com
The ShadowV2 botnet, according to Darktrace, predominantly targets misconfigured Docker containers on Amazon Web Services (AWS) cloud servers to deploy a Go-based malware that turns infected systems into attack nodes and co-opt them into a larger DDoS botnet.
-
web:www.bleepingcomputer.com
A new Mirai-based botnet malware named 'ShadowV2' has been observed targeting IoT devices from D-Link, TP-Link, and other vendors with exploits for known vulnerabilities.
-
web:www.broadcom.com
FortiGuard Labs recently reported on ShadowV2 , a Mirai-based malware , targeting IoT devices during the large-scale AWS disruption incident in October. Exploiting vulnerabilities across various vendor products, the malware utilizes a downloader script to establish C2 communication and executes multi-vector DDoS flood attacks (TCP, UDP, and HTTP).
-
web:www.fortinet.com
ShadowV2 , a new Mirai-based botnet targeting IoT devices, surfaced during the recent AWS outage. FortiGuard Labs examines its propagation, DDoS capabilities, and global footprint.
-
web:www.techworm.net
Security researchers at Fortinet's FortiGuard Labs have identified a new Mirai-based botnet called ShadowV2 that quietly emerged during the major AWS outage in October, targeting vulnerable IoT devices worldwide and disappearing soon after the outage ended.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.