TF-MAL-elf.monti
📛 Threat Title
Malware family: Monti
Description
ThreatFox malware family `elf.monti`. Printable name: Monti.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.monti
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.monti
IOC database
- Type
- domain
- Value
elf.monti- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.monti
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.monti
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
The " Monti " ransomware group has been identified as a previously unknown threat actor group, according to an analysis by BlackBerry's Incident Response team and security researchers at the University of California, San Francisco.
-
web:cybernews.com
The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.
-
web:cyberpress.org
The Military Industries State Corporation (Fabricaciones Militares Sociedad del Estado), Argentina's state-owned arms manufacturing conglomerate, has confirmed a disruptive cyberattack attributed to the MONTI ransomware group. The incident, marks one of the most severe breaches of South America's defense-industrial infrastructure, raising alarms about vulnerabilities in critical national ...
-
web:malpedia.caad.fkie.fraunhofer.de
A ransomware, derived from the leaked Conti source code.
-
web:sosransomware.com
The Monti ransomware has been in the news for some months now, thanks to targeted cyberattacks and a sophisticated infiltration strategy. Although relatively new to the scene, the ransomware has already caused significant damage to several organizations, notably in France. What is the origin of Monti ransomware? What are its attack tactics, and how can we best protect ourselves against this ...
-
web:www.bitdefender.com
According to the advisory (FLASH-20260219-001), cybercriminals are increasingly deploying sophisticated malware — particularly variants of the Ploutus family — to force Automated Teller Machines (ATMs) to dispense cash without any legitimate transaction or bank authorization.
-
web:www.digitalassetredemption.com
Monti's uncertain ownership structure highlights the importance of case-by-case investigations into potential threat actor attribution. On November 26, 2024 an announcement on the official Monti blog stated, "Publications postponed" - an indication that no further announcements of Monti's victims would be made until further notice.
-
web:www.mphasis.com
• http[:]//mblogci3rudehaagbryjznltdp33ojwzkq6hn2pckvjq33rycmzczpid.onion • http[:]//mblogci3rudehaagbryjznltdp33ojwzkq6hn2pckvjq33rycmzczpid.onion/
-
web:www.pcrisk.com
Monti continues targeting large entities, but the group has shifted its focus to institutions operating within the legal and governmental spheres. More information on these developments can be found in an article by Nathaniel Morales and Joshua Paul Ignacio on Trend Micro. MONTI ransomware removal: Instant automatic malware removal:
-
web:www.trendmicro.com
The Monti ransomware collective has restarted their operations, focusing on institutions in the legal and governmental fields. Simultaneously, a new variant of Monti , based on the Linux platform, has surfaced, demonstrating notable differences from its previous Linux-based versions.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.