CVE
CVE-2022-22947
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
Exploitation IoCs 50
Domain c2[.]tuxbot[.]local
Domain captcha[.]kanfetka[.]site
Domain cdnorigin[.]net
Domain cfcybernews[.]eu
Domain digikalas[.]online
Domain jetross[.]com
Filename .bot_x86_64
Filename tuxbot.alpha
Filename tuxbot.arm
Filename tuxbot.arm64
Filename tuxbot.arm7
Filename tuxbot.hppa
Filename tuxbot.m68k
Filename tuxbot.mips
Filename tuxbot.mips64
Filename tuxbot.mips64el
Filename tuxbot.mipsel
Filename tuxbot.ppc
Filename tuxbot.ppc64le
Filename tuxbot.riscv64
Filename tuxbot.s390x
Filename tuxbot.sh4
Filename tuxbot.sparc64
Filename tuxbot.x86_64
SHA-1 31c69b3e12936abca770d430066f379ec1d997ec
SHA-256 0f8bcca3ed65e980da2a1f90a767b7d543be32eeea3e9338d09d4d635a497988
SHA-256 146f6010f6ee082aab13e0148d39baefa77eaba4ff65817b511b08c2092bdfd2
SHA-256 15c17dce89deccd5172285b2650de957918aa1157cde8e4633ae15dfe31f2711
SHA-256 246c97957651de568e61eba1abe572f0b0f960456209995d43d53a0d7cc494a1
SHA-256 2f2c3551762c03da126e45dca6fc2f997c63f0f1bfc21fd0ceed680ac6f083ce
SHA-256 3ec016d637e4c9cd331edd2580a229621ad638e924a4aa29ac0342e9144ace19
SHA-256 511d3ffb4091cbcc94571d9fb3102e8cb424c6e187d01d53ff12078d54929bda
SHA-256 6aa4034dc7a2858094ff4dc59af07d6fe31119591e41599bcc0f3d0b516ee734
SHA-256 6b7a8e0c96c2318e747f074f9a99d26738700769ac01bba692d19fc884847737
SHA-256 71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d
SHA-256 96b1f96efca3b9df2dea85678d60da27e3265b4a00e39e20e64b27bb985e1561
SHA-256 9cd5e7e3c8bad321ef6c3d47fe25b3b56e9487f703a7eeee52db4067e6bafe61
SHA-256 a03b0d41f5ef03328150331ffa0ed970998883f7e0343d79b2d3b95330d8e7c1
SHA-256 a8d70d16509e227d8306be361bc37a3dc9fe34bf476f51e361e55e6d293c2b3f
SHA-256 bd6431fb06e4689142ef597cf00382e38ae20a5393a4d9277e45a3f5b3cbcff9
SHA-256 c7a36d6b8128c41f93a32413675401a10a2b5769b221bbaa8c5c309585b73ceb
SHA-256 e3a5296e762e9ee16010399666441d663beeea956382e97cca032a6a5ad06811
SHA-256 eb2fa179fde2f097c18d5d700ad87d660fc238ee14cbe5477032e60856859621
SHA-256 f1efb78887bb8783d7781c07cd13b53c9c79ebe5baa81f335838d0a6e73dec7e
SHA-256 f324a45fcd2a9db4e542c09486c21b08bc42d6bf76fbd5f17871090361b10815
IP 154[.]6[.]197[.]43
IP 185[.]10[.]68[.]127
IP 188[.]166[.]2[.]226
IP 209[.]182[.]237[.]133
IP 209[.]99[.]186[.]235
MITRE ATT&CK TTPs 34
T1021.002 T1027 T1055 T1059.001 T1059.004 T1071.001 T1071.004 T1078.001 T1082 T1083 T1090 T1090.001 T1090.002 T1090.003 T1090.004 T1110.001 T1133 T1190 T1203 T1210 T1218.001 T1220 T1480 T1498 T1498.001 T1566 T1571 T1572 T1573 T1573.001 T1573.002 T1573.003 T1573.004 T1659
SMB/Windows Admin Shares
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
PowerShell
Execution
Unix Shell
Execution
Web Protocols
Command And Control
DNS
Command And Control
Default Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
Internal Proxy
Command And Control
External Proxy
Command And Control
Multi-hop Proxy
Command And Control
Domain Fronting
Command And Control
Password Guessing
Credential Access
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Compiled HTML File
Defense Evasion
XSL Script Processing
Defense Evasion
Execution Guardrails
Defense Evasion
Network Denial of Service
Impact
Direct Network Flood
Impact
Phishing
Initial Access
Non-Standard Port
Command And Control
Protocol Tunneling
Command And Control
Encrypted Channel
Command And Control
Symmetric Cryptography
Command And Control
Asymmetric Cryptography
Command And Control
T1573.003
T1573.004
Content Injection
Initial Access
Source Articles
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go-based botnet named NadMesh, discovered in early July 2026, actively targets exposed AI and cloud services to harvest cloud credentials, Kubernetes tokens, and model access. The malware prioritizes exploitation of MCP (Model Context Protocol) services, Docker APIs, Jenkins consoles, and Redis instances, with a focus on credential theft rather than host compromise. The operator uses self-propagating scanning infrastructure, persistence mechanisms, and obfuscation to evade detection, while targeting specific ports associated with AI tools like ComfyUI, Ollama, Gradio, and n8n. Researchers observed real-time exploitation traffic, though success rates for MCP exploitation remain low compared to other vectors.
hacker-news Jul 17, 2026
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution is a modular IoT botnet framework leveraging LLM-assisted development, capable of DDoS attacks, device infection via Telnet brute-forcing, and persistence across multiple architectures. The malware uses encrypted C2 communication with fallback mechanisms including DGA, P2P gossip, and IRC, though several components are non-functional due to development bugs. The operator is linked to the Keksec/Kaitori ecosystem, sharing infrastructure with known IoT threats, and has active C2 servers in Singapore and a dropper in Iceland.
unit42 Jul 15, 2026