TF-MAL-elf.cd00r
📛 Threat Title
Malware family: cd00r
Description
ThreatFox malware family `elf.cd00r`. Printable name: cd00r.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
cd00r is an open-source backdoor for UNIX and UNIX-variant operating systems that was orginally released in 2000. cd00r source code is primarily based on a packet-capturing program as it utilizes a sniffer to listen for specific sequences of network traffic or "secret knock" before executing the attacker's code.
-
web:cyberpress.org
Incorporating an encrypted RSA-based challenge-response mechanism to prevent unauthorized access. While there are similarities to the "SeaSpy" malware family , such as overlapping function names and a shared use of cd00r , J-Magic's unique certificate-based challenge-response suggests advancements in operational security.
-
web:gbhackers.com
A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with a backdoor attack that leverages a passive monitoring agent. The operation, first detected in September 2023, employs a variant of the cd00r backdoor that continuously scans for specific "magic packets" in TCP traffic. Technical Implementation The malware , masquerading as ...
-
web:malpedia.caad.fkie.fraunhofer.de
A backdoor for UNIX operating systems that implements knocking as authentication method.
-
web:securityboulevard.com
The cd00r malware was configured to listen for incoming "Magic Packets" on the network, then set up a reverse shell. The Tiny Shell malware , reported by Mandiant researchers, involved six different variants of the malware , all of which "incorporate a core TINYSHELL backdoor functionality" according to Mandiant's research.
-
web:thehackernews.com
Rare malware targets Juniper routers in the J-magic campaign, exploiting JunoOS and impacting industries like IT, energy, and manufacturing.
-
web:undercodenews.com
4. Evolution of cd00r : The inclusion of an encrypted challenge-response mechanism in the J-magic backdoor indicates an evolution in the cd00r family . This added layer of authentication suggests that threat actors are investing more effort into operational security, making their campaigns harder to trace and disrupt. 5.
-
web:www.lumen.com
The intersection of cd00r , SeaSpy, and J-magic Once established on a device, the actor favors the use of open-source malware , our sample being a custom variant of cd00r . Originally released on Packet Storm in 2000 to explore the idea of an "invisible" backdoor. The project was later improved upon in 2015 then uploaded to Github; this iteration afforded more modularity such as selecting the ...
-
web:www.scworld.com
Such findings come after enterprise Juniper Networks routers were reported by Lumen Black Lotus Labs to have been subjected to intrusions spreading a cd00r backdoor variant as part of the J-magic attack campaign.
-
web:www.telecomstechnews.com
Researchers from Black Lotus Labs have identified a targeted malware campaign that exploits enterprise-grade Juniper routers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.