TF-MAL-elf.spry_socks
📛 Threat Title
Malware family: SprySOCKS
Description
ThreatFox malware family `elf.spry_socks`. Printable name: SprySOCKS.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Client data and communication closely mirror the malware used by Trochilus and RedLeaves, indicating possible inspiration or source code access. With a particular emphasis on government agencies involved in foreign affairs, technology, and telecommunications in numerous locations, Earth Lusca has continued its cyber activities.
-
web:apt.etda.or.th
Last change to this tool card: 13 October 2023 Download this tool card in JSON format All groups using tool SprySOCKS
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the SprySOCKS malware family including references, samples and yara signatures.
-
web:securityaffairs.com
China-linked threat actor Earth Lusca used a new Linux malware dubbed SprySOCKS in a recent cyber espionage campaign.
-
web:www.bleepingcomputer.com
A Chinese espionage-focused hacker tracked as 'Earth Lusca' was observed targeting government agencies in multiple countries, using a new Linux backdoor dubbed 'SprySOCKS.' Trend Micro's analysis ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.linuxjournal.com
The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities.
-
web:www.tanium.com
Threat actors repurpose old code in fake vulnerability PoC, the FBI and CISA issue a joint advisory for Snatch RaaS, and threat actors deploy new SprySOCKS Linux malware in cyberespionage attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.