TF-MAL-elf.backdoorit
📛 Threat Title
Malware family: Backdoorit
Description
ThreatFox malware family `elf.backdoorit`. Printable name: Backdoorit. Aliases: backd00rit.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.backdoorit
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.backdoorit
IOC database
- Type
- domain
- Value
elf.backdoorit- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.backdoorit
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.backdoorit
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arxiv.org
To show the generality of our proposed mitigation , we evaluate it on two clean-label model-agnostic attacks on two diferent classic cybersecurity data modalities: network flows classification and malware classification, using gradient boosting and neural network models.
-
web:cloud.google.com
In addition, Ivanti released a new enhanced external integrity checker tool (ICT) to detect potential attempts of malware persistence across factory resets and system upgrades and other tactics, techniques, and procedures (TTPs) observed in the wild. We also released a remediation and hardening guide, which includes recommendations.
-
web:hunt.io
Discover the tactics, capabilities, and associations of the Oyster backdoor malware , along with effective mitigation strategies to protect your systems.
-
web:lab52.io
The malware leverages the Application_MAPILogonComplete and Application_NewMailEx events to execute code whenever Outlook is started or a new email arrives. The project is obfuscated, with variable and function names replaced by random alphabetic strings to conceal its behavior. Additionally, the malware employs a unique string encoding technique for both internal data and dynamically ...
-
web:media.defense.gov
Introduction Note: This Malware Analysis Report was originally published Dec. 4, 2025, to share indicators of compromise (IOCs) and detection signatures for BRICKSTORM malware . The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Canadian Centre for Cyber Security (Cyber Centre) have updated this Malware Analysis Report three times.
-
web:windowsforum.com
The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .
-
web:www.cisa.gov
Malware Summary BRICKSTORM is a custom Executable and Linkable Format (ELF) Go-or Rust-based backdoor (eight originally analyzed samples are Go-based, and two of the three new samples in the Dec. 19, 2025, update are Rust-based).
-
web:www.malwarebytes.com
Backdoor.Remcos is Malwarebytes' detection name for a family of Backdoor Trojans that allow remote access and control over the affected system.
-
web:www.microsoft.com
Take these steps to help prevent malware infection on your compute r. Guidance for enterprise administrators and Microsoft 365 Defender customers Ransomware more than often attacks enterprises than individuals. Following the below mitigation steps can help prevent ransomware attacks.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.