Gafgyt malware family
Gafgyt is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-17. Observed ATT&CK techniques include T1105, T1059.004.
Corpus statistics
- Publicly analyzed samples: 7
- First seen: 2026-07-28
- Last seen: 2026-08-17
- Verdicts: malicious 7
- File types: elf 7
ATT&CK techniques used by Gafgyt
Extracted command-and-control infrastructure
- 2.2.2.2 - 2 samples
- 3.3.3.3 - 2 samples
- 4.4.4.4 - 2 samples
- 94.154.43.80 - 2 samples
- 209.244.0.3 - 1 sample
- 209.244.0.4 - 1 sample
- 4.2.2.3 - 1 sample
- 4.2.2.4 - 1 sample
- 4.2.2.5 - 1 sample
- 4.2.2.6 - 1 sample
- 83.168.110.191 - 1 sample
- 83.168.69.141 - 1 sample
- http://upx.sf.net - 1 sample
Recent Gafgyt samples
- 1e64187b5e3b5fe71d34ea555ff31961404adad83f8e0bd1ce0aad056a878d73 - malicious (2026-08-17)
- 406a984d952108f1d06e42046a354b4c279ea58b691a211209501cd073c180e3.elf - malicious (2026-08-12)
- 0020d6a69202ba61f8a7ff6cc2c332ac297b8761e1a1fde9d658c88085791a62.elf - malicious (2026-08-02)
- 04d788870638c10c73140fc9a00cefb7217e1ed6e9ff25468e87e5e3a2cf9c75.elf - malicious (2026-08-01)
- 413bccbb24fa7a2cc9b72c9f600a5ab4d0bb96deb537e7c8a5830dfeac7db759.elf - malicious (2026-07-29)
- 905648070f74afb7adca94f62308d34ed12e684192125d2153d832e13aaef5fe.elf - malicious (2026-07-28)
- 36cf9328ea3b65ec26b390235274bdb2beb4a12288a91e023f61aeb2b43d27e6.elf - malicious (2026-07-28)
Frequently asked about Gafgyt
- What is Gafgyt?
- Gafgyt is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-17. Observed ATT&CK techniques include T1105, T1059.004.
- How many Gafgyt samples have been analyzed?
- MalwareAnalyzer by Cyble holds 7 publicly analyzed samples attributed to Gafgyt, first seen 2026-07-28 and most recently 2026-08-17. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Gafgyt use?
- Across our Gafgyt samples the most frequently observed techniques are T1105 (4), T1059.004 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Gafgyt use?
- Gafgyt samples in this corpus are distributed as elf (7).
- Does Gafgyt use command-and-control infrastructure?
- Yes. 13 distinct command-and-control indicators have been extracted from Gafgyt samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Gafgyt malicious?
- 7 of 7 analyzed Gafgyt samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends