frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Mirai Variant "Gayfemboy" Infecting 15K+ Devices Daily – Mitigation Ideas?

5•garduno_AA•1h ago
Hey HN,

I’m a pentester and recently came across a new Mirai-based botnet called Gayfemboy (yes, the name sounds like a meme, but the threat is real). It’s currently infecting over 15,000 devices daily, mostly targeting routers and network gear from Cisco, TP-Link, DrayTek, and Raisecom.

What it does:

Launches DDoS attacks (UDP, TCP, ICMP) Mines Monero using XMRig Acts as a proxy for malicious traffic Installs backdoors and evades analysis (e.g., UPX header tampering, nanosecond delays)

Vulnerabilities exploited (At this moment):

CVE-2025-20281 (Cisco ISE) CVE-2023-1389 (TP-Link AX21) CVE-2020-8515 (DrayTek) CVE-2024-7120 (Raisecom MSG)

Mitigation ideas I’m testing:

Scanning client networks for vulnerable firmware Blocking known malicious domains and IPs at the firewall level Writing scripts to detect outbound traffic to those IOCs Recommending disabling remote admin access on routers I’d love to hear what others are doing to detect or contain this botnet. Has anyone seen it in enterprise environments? Any creative or effective mitigation strategies you’d recommend?

Comments

svgmaker•1h ago
This is such a joke... anyway what does this "malware" do?
galaxy_gas•1h ago
its IOT ddos/proxy botnet.

I dont know why its trying to mine crypto on a weak ARM router no way that gets far

garduno_AA•1h ago
Haha yeah, the name’s ridiculous — but the malware’s real.

It’s a Mirai variant that infects routers (Cisco, TP-Link, etc.), does DDoS, mines crypto, proxies traffic, and drops backdoors. Spreads via known and zero-day vulns.

Elon Musk Promises Full Self-Driving "Next Year"

https://www.youtube.com/watch?v=B4rdISpXigM
2•JumpinJack_Cash•1m ago•0 comments

One-Third of the Internet Is Bots Now

https://www.vice.com/en/article/yep-one-third-of-the-internet-is-just-bots-now/
2•bookofjoe•3m ago•1 comments

Nano BiBi – a free, AI creation platform powered by Google's Nano Banana

https://nanobibi.com/en
1•jokera•5m ago•1 comments

Show HN: Httpjail – HTTP(s) request filter for processes

https://github.com/coder/httpjail
1•ammario•5m ago•0 comments

I wrote an algorithm that matches you with an IRL group of nearby friends

https://klatchmaker.com/
1•v_dixon•5m ago•1 comments

Iron Vector: 50% Cost Reduction for Apache Flink Workloads

https://irontools.dev/blog/introducing-iron-vector/
1•matthewhelm•7m ago•0 comments

A Look at Not an Android Emulator

https://hackaday.com/2025/09/10/a-look-at-not-an-android-emulator/
1•wicket•8m ago•0 comments

TikTok deal 'framework' reached with China, Trump and Xi will finalize it Friday

https://www.cnbc.com/2025/09/15/trump-tiktok-china.html
2•rmason•8m ago•0 comments

"Null" breaks Swift bank transfer

https://twitter.com/matthieunapoli/status/1967559805025009931
2•bfoks•13m ago•0 comments

Lite and Text Only News and Other Websites

https://bmk.neocities.org/
2•Bender•15m ago•0 comments

Scryer Prolog Meetup 2025

https://hsd-pbsa.de/veranstaltung/scryer-prolog-meetup-2025/
2•aarroyoc•15m ago•0 comments

I'm Back, Bb

https://littlefeelings.substack.com/p/im-back-bb
1•martialg•16m ago•0 comments

A Figma plugin for Laser Cutting

https://www.heyraviteja.com/post/portfolio/laser-cuts/
1•catchmeifyoucan•19m ago•0 comments

I Am Rich (iPhone App)

https://en.wikipedia.org/wiki/I_Am_Rich
7•jethronethro•24m ago•0 comments

Beli Ate Yelp

https://www.nytimes.com/2025/09/15/dining/beli-restaurant-app.html
1•frenchman_in_ny•24m ago•0 comments

Cagot

https://en.wikipedia.org/wiki/Cagot
1•thunderbong•25m ago•0 comments

Elon Musk Buys $1B in Tesla Stock as Board Defends His Pay New York Times

https://www.nytimes.com/2025/09/15/business/elon-musk-buys-tesla-shares.html
3•janandonly•26m ago•1 comments

Airpower in the Caribbean: US Bulks Up Presence with MQ-9s, F-35s, and More

https://www.airandspaceforces.com/airpower-caribbean-us-presence-mq-9-f-35/
2•Bender•28m ago•0 comments

NY could force TikTok, YouTube, and Instagram to roll out age verification

https://www.theverge.com/news/778177/ny-safe-act-online-age-verification-social-media-proposed-rules
3•01-_-•28m ago•0 comments

Quantum Motion delivers silicon CMOS-based quantum computer

https://www.datacenterdynamics.com/en/news/quantum-motion-delivers-silicon-cmos-based-quantum-com...
2•01-_-•29m ago•0 comments

Plan a small event before you go to a big meetup

https://scyy.fi/mistakes/invite-at-hand
2•mefengl•31m ago•0 comments

Show HN: Ruminate – AI reading tool for understanding hard things

https://tryruminate.com/
5•rshanreddy•33m ago•0 comments

AI Music radio as an interactive vintage radio experience

https://radiai.appwrite.network/
1•fillskills•34m ago•1 comments

Woman Allowed to Continue Digging Tunnel Underneath Home [video]

https://www.youtube.com/watch?v=6-6ZTNs2DzI
3•CharlesW•34m ago•1 comments

Childhood collectibles outperform traditional markets

https://longnostalgia.com/
2•liszper•35m ago•1 comments

Trying to solve context for coding agents working on large complex codebases

1•ayushag132•36m ago•0 comments

Spurious Correlations

https://www.tylervigen.com/spurious-correlations/#main
1•pkdpic•36m ago•0 comments

Europe wants to turn Digital Euro (CBDC) into a stablecoin

https://antongolub.substack.com/p/europe-wants-to-turn-digital-euro
1•AvG_DXB•37m ago•0 comments

Standard Series A Docs

https://github.com/StandardCap/standard-series-a
2•pranay01•39m ago•0 comments

How to Build Predictive AI Agents [video]

https://www.youtube.com/watch?v=b883-G8rbvc
2•gk1•44m ago•0 comments