s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.spry_socks

📛 Threat Title

Malware family: SprySOCKS

Category: SprySOCKS First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.spry_socks`. Printable name: SprySOCKS.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Client data and communication closely mirror the malware used by Trochilus and RedLeaves, indicating possible inspiration or source code access. With a particular emphasis on government agencies involved in foreign affairs, technology, and telecommunications in numerous locations, Earth Lusca has continued its cyber activities.

  • web:apt.etda.or.th

    Last change to this tool card: 13 October 2023 Download this tool card in JSON format All groups using tool SprySOCKS

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the SprySOCKS malware family including references, samples and yara signatures.

  • web:securityaffairs.com

    China-linked threat actor Earth Lusca used a new Linux malware dubbed SprySOCKS in a recent cyber espionage campaign.

  • web:www.bleepingcomputer.com

    A Chinese espionage-focused hacker tracked as 'Earth Lusca' was observed targeting government agencies in multiple countries, using a new Linux backdoor dubbed 'SprySOCKS.' Trend Micro's analysis ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.linuxjournal.com

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities.

  • web:www.tanium.com

    Threat actors repurpose old code in fake vulnerability PoC, the FBI and CISA issue a joint advisory for Snatch RaaS, and threat actors deploy new SprySOCKS Linux malware in cyberespionage attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.