Flodrix
Flodrix is a botnet malware strain described in the provided content as DDoS malware. It has been delivered via exploitation of Langflow vulnerabilities. Specifically, the content states that threat actors exploited the similar and easy-to-exploit Langflow flaw CVE-2025-3248 in the prior year to spread the Flodrix botnet, and that attackers hacking Langflow AI servers were observed deploying Flodrix. The malware is therefore associated with opportunistic exploitation of internet-exposed Langflow instances. High-confidence details in the content are limited, but Flodrix is explicitly characterized as a botnet used for DDoS activity and as malware delivered following compromise of vulnerable Langflow servers.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Langflow noted that this vulnerability is distinct from CVE-2025-3248, a similar and easy-to-exploit flaw that was exploited by threat actors last year to spread the Flodrix botnet.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet referenced as having been spread by threat actors through exploitation of CVE-2025-3248 in Langflow.
Botnet malware delivered by exploiting a Langflow vulnerability; used to conduct DDoS attacks.
DDoS botnet deployed via compromise of Langflow AI servers.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.