s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.lzrd

📛 Threat Title

Malware family: LZRD

Category: LZRD First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.lzrd`. Printable name: LZRD.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.lzrd VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.lzrd

IOC database

Type
domain
Value
elf.lzrd
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.lzrd

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.lzrd

References (1)

Remediations (10)

  • web:cyberpress.org

    Remote, unauthenticated attackers are able to inject arbitrary system commands, enabling full device compromise without user interaction. Investigation revealed that threat actors are leveraging the compromised endpoint to download and execute Mirai-based ARM malware , notably a variant referred to as " LZRD " (typically named boatnet.arm7). Upon execution, this Mirai variant displays a ...

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:hackread.com

    Cybersecurity experts at Akamai have uncovered a new threat: two separate botnets are actively exploiting a critical flaw in Wazuh security software, open source XDR and SIEM solution, to spread the Mirai malware .

  • web:hivepro.com

    #3 The first emerged in early March 2025, when attackers deployed a malicious shell script that downloaded and executed a Mirai malware variant known as "morte." This particular strain belongs to the LZRD Mirai family , easily identified by the hardcoded string " lzrd here" displayed on infected systems.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Akamai, a Mirai variant exploiting GeoVision IoT devices, (possibly CVE-2024-6047 and/or CVE-2024-11120).

  • web:trustcrypt.com

    Given the increasing prevalence of IoT devices and their integration into critical systems, the urgency for thorough patching and remediation cannot be overstated. Organizations utilizing Wazuh are strongly advised to implement the necessary patches and security updates immediately to mitigate the risk posed by these exploiting botnets.

  • web:www.akamai.com

    Fig. 1: Commands to download and execute an ARM-based Mirai malware file named "boatnet" This exploit downloads and executes a Mirai-based malware variant called LZRD . The most common way to identify this variant is via the unique string it prints to the target machine's console upon execution of the malware (Figure 2).

  • web:www.broadcom.com

    The malware exploits two command injection vulnerabilities affecting GeoVision IoT devices that have been disclosed last year - CVE-2024-6047 and CVE-2024-11120. Upon a successful exploitation, the attackers attempt to download and execute ARM-based Mirai payloads - among them a variant called LZRD .

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.