TF-MAL-elf.sword2033
📛 Threat Title
Malware family: Sword2033
Description
ThreatFox malware family `elf.sword2033`. Printable name: Sword2033.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:andreafortuna.org
Alloy Taurus, a Chinese nation-state group known for attacking telecom companies since at least 2012, has been found to be using a Linux variant of the PingPull backdoor and a new tool called Sword2033 , according to cybersecurity company Palo Alto Networks Unit 42.
-
web:blog.polyswarm.io
Sword2033 | Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.
-
web:linuxsecurity.com
Hackers are deploying new Linux malware variants in cyberespionage attacks, such as a new PingPull variant and a previously undocumented backdoor tracked as 'Sword2033.'
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Sword2033 malware family including references, samples and yara signatures.
-
web:securityaffairs.com
China-linked threat actor, tracked as Alloy Taurus, is using a Linux variant of the PingPull backdoor and a new tool dubbed Sword2033 .
-
web:securityonline.info
In addition to the PingPull variant, the researchers also identified a backdoor they track as Sword2033 , linked to the same command and control (C2) infrastructure. The first samples of PingPull malware were found in September 2021, and its functionality was outlined by Unit 42 in June 2022.
-
web:unit42.paloaltonetworks.com
A PingPull malware variant for Linux has been found. We're also tracking a new backdoor attributed to Alloy Taurus called Sword2033 .
-
web:www.bleepingcomputer.com
Hackers are deploying new Linux malware variants in cyberespionage attacks, such as a new PingPull variant and a previously undocumented backdoor tracked as 'Sword2033.'
-
web:www.broadcom.com
PingPull and Sword2033 malware targeting Linux systems
-
web:www.hivepro.com
The backdoor supports three basic functions, and the command handlers for Sword2033 use the same values and functionality as PingPull. Researchers identified the C2 for Sword2033 in South Africa, and the domain name of the C2 server appears to impersonate the South African military.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.