s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.botenago

📛 Threat Title

Malware family: BotenaGo

Category: BotenaGo First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.botenago`. Printable name: BotenaGo.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.botenago VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.botenago

IOC database

Type
domain
Value
elf.botenago
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.botenago

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.botenago

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:cymulate.com

    The malware initiates a total of 33 exploit functions targeting different routers and IoT devices by calling the function "scannerInitExploits" The code contains additional configuration for a remote server, including available payloads and a path to folders that contains additional script files to execute on infected devices.

  • web:github.com

    Explore RootSec's DDOS Archive, featuring top-tier scanners, powerful botnets (Mirai & QBot) and other variants, high-impact exploits, advanced methods, and efficient sniffers. Ideal for cy...

  • web:malpedia.caad.fkie.fraunhofer.de

    BotenaGo strikes again - malware source code uploaded to GitHub BotenaGo 2022-01-12 ⋅ LIFARS Newly Found Malware Threatens IoT Devices BotenaGo 2021-11-11 ⋅ AT&T ⋅ Ofer Caspi AT&T Alien Labs finds new Golang malware ( BotenaGo ) targeting millions of routers and IoT devices with more than 30 exploits BotenaGo

  • web:rewterz.com

    Severity Medium Analysis Summary BotenaGo is a malware developed in an open-source programming language "Go" created by Google. In October 2021, the source code for Botena malware was leaked, allowing additional versions to be created based on the original. Nozomi Networks Labs uncovered a new variant of BotenaGo and named it "Lilin Scanner" which particularly targets Lilin security ...

  • web:thrive.trellix.com

    Summary Description of Campaign Millions of routers and IoT devices are being targeted by the Golang based BotenaGo malware family . Attackers are taking advantage of more than 30 vulnerabilities to infect the devices. Successful exploitation results in backdoors created, which are waiting on a target to attack or command to execute.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.keysight.com

    Recently, our Application Threat Intelligence Team (ATI) have developed a feature on Threat Simulator called Priority Risk Mitigation . This feature gives our customers access to the latest malware of concern seen in the wild in the last 24 hours, which you'll not be surprised to hear contains BotenaGo samples.

  • web:www.levelblue.com

    LevelBlue Labs recently discovered that the source code of BotenaGo malware was uploaded to GitHub on October 16th 2021, allowing any malicious hacker to use, modify, and upgrade it — or even simply compile it as is and use the source code as an exploit kit, with the potential to leverage all BotenaGo's exploits to attack vulnerable devices.

  • web:www.researchgate.net

    Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.