s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.sedexp

📛 Threat Title

Malware family: sedexp

Category: sedexp First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.sedexp`. Printable name: sedexp.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.sedexp VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sedexp

IOC database

Type
domain
Value
elf.sedexp
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.sedexp

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sedexp

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The 'sedexp' malware , has been actively evading detection since 2022, targeting Linux systems with a stealthy persistence technique that leverages udev rules, a method not yet documented in the MITRE ATT&CK framework. The malware is notable for its ability to create reverse shells, allowing attackers to remotely access compromised systems.

  • web:cybersecuritynews.com

    AON's Stroz Friedberg recently discovered a stealthy Linux malware , 'Sedexp,' having zero-detections since 2022. Stealthy Linux Malware Sedexp uses udev rules in Linux for persistence, and to avoid detection, it manipulates memory and hides these rules using more advanced methods than before.

  • web:greatis.com

    A Linux malware called 'sedexp' has remained undetected since 2022 by employing a stealthy persistence technique not currently listed in the MITRE ATT&CK framework. Discovered by risk management firm Stroz Friedberg, an Aon Insurance company, this malware allows its operators to establish reverse shells for remote access, facilitating further infiltration. "The persistence method employed ...

  • web:rewterz.com

    Analysis Summary Using a persistence method not yet included in the MITRE ATT&CK framework, the cunning Linux malware known as " sedexp " has been avoiding detection since 2022. Researchers discovered the malware , which allows its operators to build reverse shells for remote access and to intensify the attack. As of this writing, MITRE ATT&CK has not published any documentation on the ...

  • web:securityaffairs.com

    Researchers spotted a new stealthy Linux malware named sedexp that uses Linux udev rules to achieve persistence and evade detection. Aon's Cyber Solutions spotted a new malware family , called sedexp , that relies on a lesser-known Linux persistence technique. The malware has been active since at least 2022 but remained largely undetected for ...

  • web:securityboulevard.com

    A new, sophisticated Linux malware named " sedexp " has been discovered, quietly evading detection since 2022. Its unique persistence technique, leveraging udev rules, has allowed it to operate under the radar, making it a particularly dangerous threat. This article explores how this malware operates, its unique evasion strategies, and the implications for Linux security. How The post Sedexp ...

  • web:thehackernews.com

    Discover 'sedexp' , a stealthy Linux malware using udev rules for persistence, hiding credit card skimmers, and evading detection since 2022.

  • web:www.bleepingcomputer.com

    The latest news about Sedexp Stealthy 'sedexp' Linux malware evaded detection for two years A stealthy Linux malware named 'sedexp' has been evading detection since 2022 by using a persistence ...

  • web:www.levelblue.com

    Stroz Friedberg identified a stealthy malware , dubbed " sedexp ," utilizing Linux udev rules to achieve persistence and evade detection. This advanced threat, active since 2022, hides in plain sight while providing attackers with reverse shell capabilities and advanced concealment tactics.

  • web:www.techradar.com

    Stroz Friedberg, which discovered the malware and wrote an in-depth explainer, said the malware is called " sedexp ", and has been evading detection since 2022.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.