TF-MAL-jar.slaystyle
📛 Threat Title
Malware family: SLAYSTYLE
Description
ThreatFox malware family `jar.slaystyle`. Printable name: SLAYSTYLE.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
jar.slaystyle
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.slaystyle
IOC database
- Type
- domain
- Value
jar.slaystyle- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-jar.slaystyle
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.slaystyle
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cloud.google.com
BRICKSTORM is a stealthy backdoor used by suspected China-nexus actors for long-term espionage.
-
web:cyberpress.org
Other tools like SLAYSTYLE web shells pop up in /var/lib/tomcat9/, cementing persistence. ... Security teams hunting these threats should scan for key indicators. ... Dell patched this urgently; upgrade to version 6.0.3.1 HF1 or run their remediation script now. Hunt Tomcat logs for /manager hits, isolate affected appliances, and monitor VMware ...
-
web:cybersecuritynews.com
A critical zero-day exploitation campaign targeting Dell RecoverPoint for Virtual Machines. The attackers have utilized this flaw to move laterally across networks, maintain persistent access, and deploy a suite of sophisticated malware , including SLAYSTYLE , BRICKSTORM, and a novel backdoor identified as GRIMBOLT.
-
web:cyberwebspider.com
The attackers have used this Dell vulnerability to infiltrate networks, maintain access, and deploy various malware types, including SLAYSTYLE , BRICKSTORM, and a new backdoor named GRIMBOLT. Although the initial method of access remains unknown, UNC6201 has a history of targeting network edge devices like VPN concentrators to gain entry.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Mandiant, SLAYSTYLE is a webshell written in Java.
-
web:malware.news
The threat actor has also created a web shell tracked by Mandiant as SLAYSTYLE on vCenter servers. SLAYSTYLE , tracked by MITRE as BEEFLUSH, is a JavaServer Pages (JSP) web shell that functions as a backdoor. It is designed to receive and execute arbitrary operating system commands passed through an HTTP request.
-
web:petri.com
Chinese APT exploited a Dell RecoverPoint zero-day for two years, deploying malware and gaining persistent access to VMware environments.
-
web:socprime.com
How can you protect from CVE-2026-22769? Apply Dell's remediation immediately by upgrading to 6.0.3.1 HF1 or using the vendor's remediation script path, then confirm version compliance across all appliances and related management surfaces.
-
web:thehackernews.com
UNC5221 uses BRICKSTORM malware to maintain 393-day stealthy access to U.S. SaaS, legal, and tech sectors.
-
web:www.secpod.com
UNC6201 leveraged this access to deploy multiple malware families, including the SLAYSTYLE web shell, BRICKSTORM backdoor, and the GRIMBOLT persistent backdoor. Attackers established persistence by modifying internal RecoverPoint system scripts responsible for host configuration, ensuring malware execution during system operations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.