s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.pigmy_goat

📛 Threat Title

Malware family: PigmyGoat

Category: PigmyGoat First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.pigmy_goat`. Printable name: PigmyGoat.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Pygmy Goat is a piece of malware that targets Sophos XG firewall devices, enabling backdoor access for threat actors. The malware is a native x86-32 ELF shared object that leverages the LD_PRELOAD environment variable to load itself into the sshd (SSH daemon) binary, allowing it to intercept and control SSH connections.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:decybr.com

    A goat in the firewall The 'Pygmy Goat' malware is an x86-32 ELF shared object ('libsophos.so') providing threat actors with backdoor access to Linux-based networking devices such as the Sophos XG firewalls.

  • web:greatis.com

    The UK's National Cyber Security Centre (NCSC) released an analysis on "Pygmy Goat," a sophisticated Linux malware crafted to breach Sophos XG firewall devices, linking it to attacks by suspected Chinese actors.

  • web:www.bleepingcomputer.com

    The 'Pygmy Goat' malware is an x86-32 ELF shared object ('libsophos.so') providing threat actors with backdoor access to Linux-based networking devices such as the Sophos XG firewalls.

  • web:www.cyberstash.com

    Context "Pygmy Goat" malware is a highly sophisticated backdoor payload engineered to facilitate unau-thorized access to Linux-based network devices, with a particular focus on Sophos XG firewall ap-pliances. Discovered as part of an ongoing series of cyber-espionage operations linked to Chinese state-sponsored threat actors, the malware is emblematic of the broader Pacific Rim campaign, a ...

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.ncsc.gov.uk

    Pygmy Goat forks a new execution of crontab using the statically compiled embedded BusyBox instance, otherwise operating similarly to the previous two commands.

  • web:www.securityweek.com

    The agency believes the malware was been designed to target a broader range of Linux-based network devices beyond just Sophos firewalls. The agency said it observed Pygmy Goat malware using a fraudulent certificate masquerading as one from Fortinet, another oft-targeted major firewall vendor.

  • web:www.techradar.com

    Pygmy Goat Being a sophisticated network malware , Pygmy Goat was able to disguise malicious traffic as legitimate Secure Shell (SSH) connections, and thus evade detection.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.