TF-MAL-elf.pumakit
📛 Threat Title
Malware family: PUMAKIT
Description
ThreatFox malware family `elf.pumakit`. Printable name: PUMAKIT. Aliases: PUMA,Kitsune.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.pumakit
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pumakit
IOC database
- Type
- domain
- Value
elf.pumakit- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.pumakit
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pumakit
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:1337-42.github.io
PUMAKIT isn't your everyday piece of malware—it's a cunning Linux rootkit that stays hidden in plain sight. Through a mix of memory-only binaries, loadable kernel modules, and clever syscall hooking, it achieves deep system infiltration without leaving obvious footprints behind. Unlike traditional rootkits, PUMAKIT twists even the simplest commands to its advantage, using tactics like ...
-
web:cybersecsentinel.com
Threat Group: Unknown Threat Type: Rootkit Exploited Vulnerabilities: Targets Linux kernels prior to version 5.7 Malware Used: PUMAKIT Threat Score: High (8.0/10) - Due to its advanced stealth capabilities and potential impact on critical infrastructure. Last Threat Observation: December 13, 2024, by Elastic Security Labs Overview PUMAKIT is
-
web:cybersecuritynews.com
Security researchers at Elastic Security Labs have uncovered a sophisticated Linux malware dubbed PUMAKIT , which employs advanced stealth techniques and unique privilege escalation methods to maintain persistence on infected systems.
-
web:hivepro.com
Malware : PUMAKIT Attack: A newly discovered Linux rootkit malware , named Pumakit , employs sophisticated stealth techniques and advanced privilege escalation methods to remain undetected on compromised systems. This malware is a multi-faceted threat, consisting of several components: a dropper, memory-resident executables, a kernel module rootkit, and a shared object (SO) userland rootkit. This ...
-
web:linuxsecurity.com
The recently discovered PUMAKIT loadable kernel module (LKM) rootkit stands out as an advanced example of multi-stage malware , operating over multiple stages to avoid detection and establish control on targeted systems. It does not simply plant malicious software; instead. It involves an intricate web of activities starting with droppers, memory executables, and rootkits before finally ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to Elastic, PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain communication with command-and-control servers. The rootkit component, referenced by the malware authors as "PUMA", employs an internal Linux function tracer (ftrace) to hook 18 different syscalls and several kernel functions ...
-
web:securityaffairs.com
The LKM rootkit demonstrates this behavior" The rmdir_hook() function in PUMAKIT's kernel module intercepts rmdir() syscalls to manipulate directory operations. The malware uses it for privilege escalation and to retrieve configuration details based on a structured input pattern.
-
web:www.bleepingcomputer.com
A new Linux rootkit malware called Pumakit has been discovered that uses stealth and advanced privilege escalation techniques to hide its presence on systems.
-
web:www.elastic.co
Concluding Statement PUMAKIT is a complex and stealthy threat that uses advanced techniques like syscall hooking, memory-resident execution, and unique privilege escalation methods. Its multi-architectural design highlights the growing sophistication of malware targeting Linux systems. Elastic Security Labs will continue to analyze PUMAKIT , monitor its behavior, and track any updates or new ...
-
web:www.rgrosec.com
Declawing PUMAKIT Overview At Elastic Security Labs, we uncovered PUMAKIT , a sophisticated multi-stage Linux malware with advanced rootkit capabilities. Initially identified through routine threat hunting on VirusTotal, PUMAKIT consists of a dropper (cron), two memory-resident executables, an LKM rootkit module, and a userland shared object (SO) rootkit.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.