TF-MAL-elf.lzrd
📛 Threat Title
Malware family: LZRD
Description
ThreatFox malware family `elf.lzrd`. Printable name: LZRD.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.lzrd
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.lzrd
IOC database
- Type
- domain
- Value
elf.lzrd- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.lzrd
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.lzrd
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
Remote, unauthenticated attackers are able to inject arbitrary system commands, enabling full device compromise without user interaction. Investigation revealed that threat actors are leveraging the compromised endpoint to download and execute Mirai-based ARM malware , notably a variant referred to as " LZRD " (typically named boatnet.arm7). Upon execution, this Mirai variant displays a ...
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:hackread.com
Cybersecurity experts at Akamai have uncovered a new threat: two separate botnets are actively exploiting a critical flaw in Wazuh security software, open source XDR and SIEM solution, to spread the Mirai malware .
-
web:hivepro.com
#3 The first emerged in early March 2025, when attackers deployed a malicious shell script that downloaded and executed a Mirai malware variant known as "morte." This particular strain belongs to the LZRD Mirai family , easily identified by the hardcoded string " lzrd here" displayed on infected systems.
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Akamai, a Mirai variant exploiting GeoVision IoT devices, (possibly CVE-2024-6047 and/or CVE-2024-11120).
-
web:trustcrypt.com
Given the increasing prevalence of IoT devices and their integration into critical systems, the urgency for thorough patching and remediation cannot be overstated. Organizations utilizing Wazuh are strongly advised to implement the necessary patches and security updates immediately to mitigate the risk posed by these exploiting botnets.
-
web:www.akamai.com
Fig. 1: Commands to download and execute an ARM-based Mirai malware file named "boatnet" This exploit downloads and executes a Mirai-based malware variant called LZRD . The most common way to identify this variant is via the unique string it prints to the target machine's console upon execution of the malware (Figure 2).
-
web:www.broadcom.com
The malware exploits two command injection vulnerabilities affecting GeoVision IoT devices that have been disclosed last year - CVE-2024-6047 and CVE-2024-11120. Upon a successful exploitation, the attackers attempt to download and execute ARM-based Mirai payloads - among them a variant called LZRD .
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.