TF-MAL-elf.rakos
📛 Threat Title
Malware family: Rakos
Description
ThreatFox malware family `elf.rakos`. Printable name: Rakos.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.rakos
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rakos
IOC database
- Type
- domain
- Value
elf.rakos- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.rakos
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rakos
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecsentinel.com
This malware can persist across reboots and incorporates advanced obfuscation and anti-debugging techniques to evade detection. Its primary functions include data theft, espionage, and unauthorized access to infected devices, where it can capture keystrokes, logins, financial details, and other confidential information.
-
web:malpedia.caad.fkie.fraunhofer.de
Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers. Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns. Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user. Remcos is ...
-
web:www.elastic.co
This malware research article describes the REMCOS implant at a high level, and provides background for future articles in this multipart series.
-
web:www.ic3.gov
Overview Threat actors are deploying ATM jackpotting malware , including the Ploutus family malware , to infect ATMs and force them to dispense cash. Ploutus malware exploits the eXtensions for Financial Services (XFS), the layer of software that instructs an ATM what to physically do. When a legitimate transaction occurs, the ATM application sends instructions through XFS for bank authorization ...
-
web:www.malwarebytes.com
Backdoor.Remcos is Malwarebytes' detection name for a family of Backdoor Trojans that allow remote access and control over the affected system.
-
web:www.mcafee.com
In Q3 2024, McAfee Labs identified a sharp rise in the Remcos RAT threat. It has emerged as a significant threat in the world of cybersecurity, gaining traction with its ability to infiltrate systems and compromise sensitive data. This malware , often delivered through phishing emails and malicious attachments, allows cybercriminals to remotely control infected machines, making it a powerful ...
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.pcrisk.com
The malware also abuses legitimate Windows tools to make its activity merge with normal system behavior. It communicates with a command-and-control server controlled by the attacker, allowing the attacker to send remote instructions to the infected device. Eventually, the full Remcos RAT payload is delivered. Instant automatic malware removal:
-
web:www.picussecurity.com
Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.
-
web:www.sentinelone.com
Understand what kind of demands Rook Ransomware makes to corporate networks and multi-extortion victims. Prevent its spread, mitigate it, and be aware of how it works.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.