s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-jar.slaystyle

📛 Threat Title

Malware family: SLAYSTYLE

Category: SLAYSTYLE First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `jar.slaystyle`. Printable name: SLAYSTYLE.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain jar.slaystyle VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.slaystyle

IOC database

Type
domain
Value
jar.slaystyle
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-jar.slaystyle

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.slaystyle

References (1)

Remediations (10)

  • web:cloud.google.com

    BRICKSTORM is a stealthy backdoor used by suspected China-nexus actors for long-term espionage.

  • web:cyberpress.org

    Other tools like SLAYSTYLE web shells pop up in /var/lib/tomcat9/, cementing persistence. ... Security teams hunting these threats should scan for key indicators. ... Dell patched this urgently; upgrade to version 6.0.3.1 HF1 or run their remediation script now. Hunt Tomcat logs for /manager hits, isolate affected appliances, and monitor VMware ...

  • web:cybersecuritynews.com

    A critical zero-day exploitation campaign targeting Dell RecoverPoint for Virtual Machines. The attackers have utilized this flaw to move laterally across networks, maintain persistent access, and deploy a suite of sophisticated malware , including SLAYSTYLE , BRICKSTORM, and a novel backdoor identified as GRIMBOLT.

  • web:cyberwebspider.com

    The attackers have used this Dell vulnerability to infiltrate networks, maintain access, and deploy various malware types, including SLAYSTYLE , BRICKSTORM, and a new backdoor named GRIMBOLT. Although the initial method of access remains unknown, UNC6201 has a history of targeting network edge devices like VPN concentrators to gain entry.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Mandiant, SLAYSTYLE is a webshell written in Java.

  • web:malware.news

    The threat actor has also created a web shell tracked by Mandiant as SLAYSTYLE on vCenter servers. SLAYSTYLE , tracked by MITRE as BEEFLUSH, is a JavaServer Pages (JSP) web shell that functions as a backdoor. It is designed to receive and execute arbitrary operating system commands passed through an HTTP request.

  • web:petri.com

    Chinese APT exploited a Dell RecoverPoint zero-day for two years, deploying malware and gaining persistent access to VMware environments.

  • web:socprime.com

    How can you protect from CVE-2026-22769? Apply Dell's remediation immediately by upgrading to 6.0.3.1 HF1 or using the vendor's remediation script path, then confirm version compliance across all appliances and related management surfaces.

  • web:thehackernews.com

    UNC5221 uses BRICKSTORM malware to maintain 393-day stealthy access to U.S. SaaS, legal, and tech sectors.

  • web:www.secpod.com

    UNC6201 leveraged this access to deploy multiple malware families, including the SLAYSTYLE web shell, BRICKSTORM backdoor, and the GRIMBOLT persistent backdoor. Attackers established persistence by modifying internal RecoverPoint system scripts responsible for host configuration, ensuring malware execution during system operations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.