TF-MAL-elf.pigmy_goat
📛 Threat Title
Malware family: PigmyGoat
Description
ThreatFox malware family `elf.pigmy_goat`. Printable name: PigmyGoat.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Pygmy Goat is a piece of malware that targets Sophos XG firewall devices, enabling backdoor access for threat actors. The malware is a native x86-32 ELF shared object that leverages the LD_PRELOAD environment variable to load itself into the sshd (SSH daemon) binary, allowing it to intercept and control SSH connections.
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:decybr.com
A goat in the firewall The 'Pygmy Goat' malware is an x86-32 ELF shared object ('libsophos.so') providing threat actors with backdoor access to Linux-based networking devices such as the Sophos XG firewalls.
-
web:greatis.com
The UK's National Cyber Security Centre (NCSC) released an analysis on "Pygmy Goat," a sophisticated Linux malware crafted to breach Sophos XG firewall devices, linking it to attacks by suspected Chinese actors.
-
web:www.bleepingcomputer.com
The 'Pygmy Goat' malware is an x86-32 ELF shared object ('libsophos.so') providing threat actors with backdoor access to Linux-based networking devices such as the Sophos XG firewalls.
-
web:www.cyberstash.com
Context "Pygmy Goat" malware is a highly sophisticated backdoor payload engineered to facilitate unau-thorized access to Linux-based network devices, with a particular focus on Sophos XG firewall ap-pliances. Discovered as part of an ongoing series of cyber-espionage operations linked to Chinese state-sponsored threat actors, the malware is emblematic of the broader Pacific Rim campaign, a ...
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.ncsc.gov.uk
Pygmy Goat forks a new execution of crontab using the statically compiled embedded BusyBox instance, otherwise operating similarly to the previous two commands.
-
web:www.securityweek.com
The agency believes the malware was been designed to target a broader range of Linux-based network devices beyond just Sophos firewalls. The agency said it observed Pygmy Goat malware using a fraudulent certificate masquerading as one from Fortinet, another oft-targeted major firewall vendor.
-
web:www.techradar.com
Pygmy Goat Being a sophisticated network malware , Pygmy Goat was able to disguise malicious traffic as legitimate Secure Shell (SSH) connections, and thus evade detection.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.