TF-MAL-elf.xdr33
📛 Threat Title
Malware family: xdr33
Description
ThreatFox malware family `elf.xdr33`. Printable name: xdr33.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:archive.orkl.eu
To summarize, xdr33 is a backdoor born from the CIA Hive project, its main purpose is to collect sensitive information and provide a foothold for subsequent intrusions. In terms of network communication, xdr33 uses XTEA or AES algorithm to encrypt the original traffic, and uses SSL with Client-Certificate Authentication mode enabled to further protect the traffic; in terms of function, there ...
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as xdr33 .
-
web:blog.netlab.360.com
This is the first time we caught a variant of the CIA HIVE attack kit in the wild, and we named it xdr33 based on its embedded Bot-side certificate CN=xdr33. To summarize, xdr33 is a backdoor born from the CIA Hive project, its main purpose is to collect sensitive information and provide a foothold for subsequent intrusions.
-
web:candid.technology
Following its release by WikiLeaks in 2017, the CIA's leaked Hive malware suite has been adapted by unidentified threat actors to be deployed as a new backdoor dubbed xdr33 . It was spotted by Netlab 360's Alex Turing and Hui Wang when the cybersecurity company's honeypot system captured a suspicious ELS file propagating via F5 vulnerability with zero VT detection.
-
web:cybersecuritynews.com
Additionally, the malware is capable of executing commands issued by the C2 server, allowing the attackers to control the infected system remotely. Beacon C2 and xdr33 communicate using the following four steps as a result of the communication process and here they are mentioned below:- Two-way SSL authentication Obtain XTEA key
-
web:github.com
A modified version of xdr33 C2 malware framework created by the CIA - agnij-dutta/Spearhead
-
web:malpedia.caad.fkie.fraunhofer.de
According to 360 netlab, this backdoor was derived from the leaked CIA Hive project. It propagates via a vulnerability in F5 and communicates using SSL with a forged Kaspersky certificate.
-
web:my.f5.com
A blog published recently by third-party researchers (360Netlab) has documented an instance of a BIG-IP being compromised by an unnamed vulnerability in order to deliver malware , dubbed xdr33 , onto the device.
-
web:securityaffairs.com
Additional analysis revealed that the malware borrows code from the Hive project that was leaked in 2017 as part of Vault 8 series. This is the first time that the experts captured a variant of the CIA HIVE malware in the wild, the experts tracked is as " xdr33 " based on its embedded Bot-side certificate CN=xdr33.
-
web:www.linkedin.com
Unidentified threat actors have deployed a new backdoor that borrows its features from the U.S. Central Intelligence Agency (CIA)'s Hive multi-platform malware suite, the source code of which was ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.