s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.ballista

📛 Threat Title

Malware family: Ballista

Category: Ballista First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.ballista`. Printable name: Ballista.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.ballista VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ballista

IOC database

Type
domain
Value
elf.ballista
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.ballista

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ballista

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The Ballista botnet propagates by exploiting CVE-2023-1389, initially delivering a malware dropper via a bash script that downloads and executes the payload. The malware then removes its traces from the system to evade detection and establishes an encrypted command and control (C2) channel. Through this channel, attackers can execute shell commands, conduct DoS attacks, and attempt to access ...

  • web:cyberinsider.com

    A new global IoT botnet campaign dubbed " Ballista " targets TP-Link Archer routers via a known remote code execution (RCE) vulnerability. The botnet is actively targeting thousands of devices worldwide, spreading automatically and evolving its tactics to evade detection.

  • web:fieldeffect.com

    The researchers assess, with moderate confidence, that Ballista is controlled by an unnamed threat actor based in Italy due to the discovery of an IP address and strings in the malware binary file indicating as much. They named the botnet Ballista in a nod to the ancient Roman missile launcher. Source: SecurityWeek Analysis TP-Link routers are a popular choice among consumers looking for a ...

  • web:iotm2mcouncil.org

    The Ballista botnet has targeted manufacturing, medical, healthcare, services and technology organisations in the USA, Australia, China and Mexico. Using a Censys search, Cato CTRL identified more than 6000 vulnerable devices connected to the internet.

  • web:malpedia.caad.fkie.fraunhofer.de

    Ballista is an IoT botnet, infecting unpatched TP-Link Archer AX21 (AX1800) routers. It spreads through automatic exploitation of CVE-2023-1389. Its capabilities include remote code execution and DDoS attacks.

  • web:rhyno.io

    Overview A new botnet, known as Ballista , is now attacking TP-Link Archer routers that haven't been updated. According to researchers at Cato CTRL, the botnet takes advantage of a serious flaw (CVE-2023-1389) in these devices. This weakness lets hackers send commands to the router remotely, putting it at risk of full takeover. You might be interested in: This LightSpy Malware Steals Your ...

  • web:thehackernews.com

    The earliest evidence of active exploitation of the flaw dates back to April 2023, with unidentified threat actors using it to drop Mirai botnet malware . Since then, it has also been abused to propagate other malware families like Condi and AndroxGh0st . Cato CTRL said it detected the Ballista campaign on January 10, 2025.

  • web:www.betterworldtechnology.com

    The Ballista botnet has been identified as a significant threat, leveraging a high-severity security flaw in TP-Link routers. The vulnerability allows attackers to execute arbitrary code remotely, which can lead to severe consequences, including unauthorized access and control over infected devices.

  • web:www.catonetworks.com

    The Ballista botnet has targeted manufacturing, medical/healthcare, services, and technology organizations. Cato CTRL identified more than 6,000 vulnerable devices connected to the Internet

  • web:www.tomsguide.com

    The Ballista malware is additionally capable of terminating previous instances of itself - and erasing its own presence once execution begins.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.