s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.cd00r

📛 Threat Title

Malware family: cd00r

Category: cd00r First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.cd00r`. Printable name: cd00r.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    cd00r is an open-source backdoor for UNIX and UNIX-variant operating systems that was orginally released in 2000. cd00r source code is primarily based on a packet-capturing program as it utilizes a sniffer to listen for specific sequences of network traffic or "secret knock" before executing the attacker's code.

  • web:cyberpress.org

    Incorporating an encrypted RSA-based challenge-response mechanism to prevent unauthorized access. While there are similarities to the "SeaSpy" malware family , such as overlapping function names and a shared use of cd00r , J-Magic's unique certificate-based challenge-response suggests advancements in operational security.

  • web:gbhackers.com

    A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with a backdoor attack that leverages a passive monitoring agent. The operation, first detected in September 2023, employs a variant of the cd00r backdoor that continuously scans for specific "magic packets" in TCP traffic. Technical Implementation The malware , masquerading as ...

  • web:malpedia.caad.fkie.fraunhofer.de

    A backdoor for UNIX operating systems that implements knocking as authentication method.

  • web:securityboulevard.com

    The cd00r malware was configured to listen for incoming "Magic Packets" on the network, then set up a reverse shell. The Tiny Shell malware , reported by Mandiant researchers, involved six different variants of the malware , all of which "incorporate a core TINYSHELL backdoor functionality" according to Mandiant's research.

  • web:thehackernews.com

    Rare malware targets Juniper routers in the J-magic campaign, exploiting JunoOS and impacting industries like IT, energy, and manufacturing.

  • web:undercodenews.com

    4. Evolution of cd00r : The inclusion of an encrypted challenge-response mechanism in the J-magic backdoor indicates an evolution in the cd00r family . This added layer of authentication suggests that threat actors are investing more effort into operational security, making their campaigns harder to trace and disrupt. 5.

  • web:www.lumen.com

    The intersection of cd00r , SeaSpy, and J-magic Once established on a device, the actor favors the use of open-source malware , our sample being a custom variant of cd00r . Originally released on Packet Storm in 2000 to explore the idea of an "invisible" backdoor. The project was later improved upon in 2015 then uploaded to Github; this iteration afforded more modularity such as selecting the ...

  • web:www.scworld.com

    Such findings come after enterprise Juniper Networks routers were reported by Lumen Black Lotus Labs to have been subjected to intrusions spreading a cd00r backdoor variant as part of the J-magic attack campaign.

  • web:www.telecomstechnews.com

    Researchers from Black Lotus Labs have identified a targeted malware campaign that exploits enterprise-grade Juniper routers.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.