TF-MAL-elf.botenago
📛 Threat Title
Malware family: BotenaGo
Description
ThreatFox malware family `elf.botenago`. Printable name: BotenaGo.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.botenago
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.botenago
IOC database
- Type
- domain
- Value
elf.botenago- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.botenago
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.botenago
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:cymulate.com
The malware initiates a total of 33 exploit functions targeting different routers and IoT devices by calling the function "scannerInitExploits" The code contains additional configuration for a remote server, including available payloads and a path to folders that contains additional script files to execute on infected devices.
-
web:github.com
Explore RootSec's DDOS Archive, featuring top-tier scanners, powerful botnets (Mirai & QBot) and other variants, high-impact exploits, advanced methods, and efficient sniffers. Ideal for cy...
-
web:malpedia.caad.fkie.fraunhofer.de
BotenaGo strikes again - malware source code uploaded to GitHub BotenaGo 2022-01-12 ⋅ LIFARS Newly Found Malware Threatens IoT Devices BotenaGo 2021-11-11 ⋅ AT&T ⋅ Ofer Caspi AT&T Alien Labs finds new Golang malware ( BotenaGo ) targeting millions of routers and IoT devices with more than 30 exploits BotenaGo
-
web:rewterz.com
Severity Medium Analysis Summary BotenaGo is a malware developed in an open-source programming language "Go" created by Google. In October 2021, the source code for Botena malware was leaked, allowing additional versions to be created based on the original. Nozomi Networks Labs uncovered a new variant of BotenaGo and named it "Lilin Scanner" which particularly targets Lilin security ...
-
web:thrive.trellix.com
Summary Description of Campaign Millions of routers and IoT devices are being targeted by the Golang based BotenaGo malware family . Attackers are taking advantage of more than 30 vulnerabilities to infect the devices. Successful exploitation results in backdoors created, which are waiting on a target to attack or command to execute.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.keysight.com
Recently, our Application Threat Intelligence Team (ATI) have developed a feature on Threat Simulator called Priority Risk Mitigation . This feature gives our customers access to the latest malware of concern seen in the wild in the last 24 hours, which you'll not be surprised to hear contains BotenaGo samples.
-
web:www.levelblue.com
LevelBlue Labs recently discovered that the source code of BotenaGo malware was uploaded to GitHub on October 16th 2021, allowing any malicious hacker to use, modify, and upgrade it — or even simply compile it as is and use the source code as an exploit kit, with the potential to leverage all BotenaGo's exploits to attack vulnerable devices.
-
web:www.researchgate.net
Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.