TF-MAL-elf.shortleash
📛 Threat Title
Malware family: ShortLeash
Description
ThreatFox malware family `elf.shortleash`. Printable name: ShortLeash.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.shortleash
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.shortleash
IOC database
- Type
- domain
- Value
elf.shortleash- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.shortleash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.shortleash
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
A sophisticated cyber-espionage campaign designated "LapDogs" has compromised more than 1,000 Small Office/Home Office (SOHO) devices worldwide, leveraging a custom backdoor dubbed " ShortLeash " and establishing an Operational Relay Box (ORB) network for covert and persistent operations. Threat researchers assess this activity as a significant escalation in the use of ORB networks ...
-
web:cybersecuritynews.com
The ShortLeash Backdoor: Technical Architecture and Persistence Mechanisms The LapDogs campaign's technical sophistication centers around " ShortLeash ," a custom backdoor malware specifically designed for establishing persistent footholds on compromised SOHO devices.
-
web:expel.com
Additionally, they found a custom piece of malware deployed on the compromised devices, a backdoor they called ShortLeash , which generates the self-signed TLS certificates with spoofed metadata attributed to the LAPD.
-
web:gbhackers.com
A Technical Dissection of Persistence and Deception At the heart of LapDogs' operations is ShortLeash , a bespoke malware with variants for Linux and Windows systems, designed to ensure persistence and anonymity.
-
web:hackread.com
ShortLeash backdoor, used in the China's LapDogs attack, enables access, persistence, and data theft via hacked SOHO routers and fake certs.
-
web:malpedia.caad.fkie.fraunhofer.de
According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network. It generates unique, self-signed TLS certificates with spoofed metadata for each node. Analysis of these certificates revealed over 1000 active nodes globally and victimology supports attribution to China-Nexus APTs.
-
web:securityscorecard.com
Our analysis traces these certificates to over 1,000 actively infected nodes globally, revealing geographical targeting patterns indicative of structured tasking. ShortLeash enables unnoticed operation with high-level privileges, creating backups for persistence. Forensic evidence, including Mandarin developer notes within the startup script, tools, techniques, and procedures (TTPs), and ...
-
web:thehackernews.com
China-linked hackers use compromised SOHO devices in espionage campaign, targeting Taiwan, the U.S., and Southeast Asia.
-
web:windowsforum.com
Central to the LapDogs campaign is the deployment of a custom backdoor malware named " ShortLeash ." This malware is designed to establish persistent access on compromised devices, enabling attackers to operate undetected.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.