s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.shortleash

📛 Threat Title

Malware family: ShortLeash

Category: ShortLeash First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.shortleash`. Printable name: ShortLeash.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.shortleash VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.shortleash

IOC database

Type
domain
Value
elf.shortleash
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.shortleash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.shortleash

References (1)

Remediations (10)

  • web:cyberpress.org

    A sophisticated cyber-espionage campaign designated "LapDogs" has compromised more than 1,000 Small Office/Home Office (SOHO) devices worldwide, leveraging a custom backdoor dubbed " ShortLeash " and establishing an Operational Relay Box (ORB) network for covert and persistent operations. Threat researchers assess this activity as a significant escalation in the use of ORB networks ...

  • web:cybersecuritynews.com

    The ShortLeash Backdoor: Technical Architecture and Persistence Mechanisms The LapDogs campaign's technical sophistication centers around " ShortLeash ," a custom backdoor malware specifically designed for establishing persistent footholds on compromised SOHO devices.

  • web:expel.com

    Additionally, they found a custom piece of malware deployed on the compromised devices, a backdoor they called ShortLeash , which generates the self-signed TLS certificates with spoofed metadata attributed to the LAPD.

  • web:gbhackers.com

    A Technical Dissection of Persistence and Deception At the heart of LapDogs' operations is ShortLeash , a bespoke malware with variants for Linux and Windows systems, designed to ensure persistence and anonymity.

  • web:hackread.com

    ShortLeash backdoor, used in the China's LapDogs attack, enables access, persistence, and data theft via hacked SOHO routers and fake certs.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network. It generates unique, self-signed TLS certificates with spoofed metadata for each node. Analysis of these certificates revealed over 1000 active nodes globally and victimology supports attribution to China-Nexus APTs.

  • web:securityscorecard.com

    Our analysis traces these certificates to over 1,000 actively infected nodes globally, revealing geographical targeting patterns indicative of structured tasking. ShortLeash enables unnoticed operation with high-level privileges, creating backups for persistence. Forensic evidence, including Mandarin developer notes within the startup script, tools, techniques, and procedures (TTPs), and ...

  • web:thehackernews.com

    China-linked hackers use compromised SOHO devices in espionage campaign, targeting Taiwan, the U.S., and Southeast Asia.

  • web:windowsforum.com

    Central to the LapDogs campaign is the deployment of a custom backdoor malware named " ShortLeash ." This malware is designed to establish persistent access on compromised devices, enabling attackers to operate undetected.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.