s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.sword2033

📛 Threat Title

Malware family: Sword2033

Category: Sword2033 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.sword2033`. Printable name: Sword2033.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:andreafortuna.org

    Alloy Taurus, a Chinese nation-state group known for attacking telecom companies since at least 2012, has been found to be using a Linux variant of the PingPull backdoor and a new tool called Sword2033 , according to cybersecurity company Palo Alto Networks Unit 42.

  • web:blog.polyswarm.io

    Sword2033 | Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

  • web:linuxsecurity.com

    Hackers are deploying new Linux malware variants in cyberespionage attacks, such as a new PingPull variant and a previously undocumented backdoor tracked as 'Sword2033.'

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Sword2033 malware family including references, samples and yara signatures.

  • web:securityaffairs.com

    China-linked threat actor, tracked as Alloy Taurus, is using a Linux variant of the PingPull backdoor and a new tool dubbed Sword2033 .

  • web:securityonline.info

    In addition to the PingPull variant, the researchers also identified a backdoor they track as Sword2033 , linked to the same command and control (C2) infrastructure. The first samples of PingPull malware were found in September 2021, and its functionality was outlined by Unit 42 in June 2022.

  • web:unit42.paloaltonetworks.com

    A PingPull malware variant for Linux has been found. We're also tracking a new backdoor attributed to Alloy Taurus called Sword2033 .

  • web:www.bleepingcomputer.com

    Hackers are deploying new Linux malware variants in cyberespionage attacks, such as a new PingPull variant and a previously undocumented backdoor tracked as 'Sword2033.'

  • web:www.broadcom.com

    PingPull and Sword2033 malware targeting Linux systems

  • web:www.hivepro.com

    The backdoor supports three basic functions, and the command handlers for Sword2033 use the same values and functionality as PingPull. Researchers identified the C2 for Sword2033 in South Africa, and the domain name of the C2 server appears to impersonate the South African military.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.