s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.reptile

📛 Threat Title

Malware family: reptile

Category: reptile First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.reptile`. Printable name: reptile.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.reptile VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.reptile

IOC database

Type
domain
Value
elf.reptile
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.reptile

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.reptile

References (1)

Remediations (10)

  • web:asec.ahnlab.com

    Reptile is an open-source kernel module rootkit that targets Linux systems and is publicly available on GitHub. [1] Rootkits are malware that possess the capability to conceal themselves or other malware . They primarily target files, processes, and network communications for their concealment. Reptile's concealment capabilities include not only its own kernel module but also files ...

  • web:attack.mitre.org

    REPTILE is an open-source Linux rootkit with multiple components that provides backdoor access and functionality. [1]

  • web:cyberpills.news

    Prevention and mitigation : defend against Reptile Given the broad threat posed by Reptile , IT industry experts recommend a number of preventative measures. Making users aware of online safety practices, updating the operating system regularly, and using sophisticated anti- malware tools are of paramount importance.

  • web:cybersecuritynews.com

    The cybersecurity researchers at ASEC recently identified this new rootkit malware . Rootkit Malware Attacking Linux Systems Reptile aids malware installation and equips attackers with Listener, a command line tool that awaits a reverse shell connection to execute on infected systems, granting control to the attacker.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the reptile malware family including references, samples and yara signatures.

  • web:positka.com

    The Reptile rootkit's emergence poses a considerable hazard to Linux systems, particularly within the South Korean landscape. Distinguished by its reverse shell proficiency and strategic employment of Port Knocking, its capacity to evade detection through magic packet-based triggers underscores its covert nature.

  • web:securityaffairs.com

    Researchers observed threat actors that are using an open-source rootkit called Reptile in attacks aimed at systems in South Korea. Reptile is an open-source kernel module rootkit that was designed to target Linux systems, unlike other rootkits, it also offers a reverse shell. The malware supports port knocking, it opens a specific port on an infected system and waits for a Magic Packet sent ...

  • web:thehackernews.com

    Threat actors are using an open-source rootkit called Reptile to target Linux systems in South Korea. "Unlike other rootkit malware that typically only provide concealment capabilities, Reptile goes a step further by offering a reverse shell, allowing threat actors to easily take control of systems ...

  • web:www.cybermaterial.com

    In the ever-evolving landscape of cybersecurity threats, Reptile malware has emerged as a particularly concerning actor, targeting Linux systems with sophisticated techniques. Reptile is a sophisticated open-source rootkit designed to operate stealthily within the kernel of Linux-based systems, making it a formidable challenge for system administrators and cybersecurity professionals. Unlike ...

  • web:www.hivepro.com

    A Chinese threat group named UNC3886, exploited it in a zero-day attack on Fortinet products. Interestingly, Reptile shares #4 similarities with the Mélofée malware , linking it to the Chinese Winnti attack group. This highlights Reptile's role as an enabler for attackers seeking to breach systems and maintain control over compromised ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.