s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.krustyloader

📛 Threat Title

Malware family: KrustyLoader

Category: KrustyLoader First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.krustyloader`. Printable name: KrustyLoader.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.krustyloader VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.krustyloader

IOC database

Type
domain
Value
elf.krustyloader
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.krustyloader

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.krustyloader

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The emergence of a new threat in the form of KrustyLoader , a Rust-based backdoor actively targeting both Windows and Linux operating systems. With its emphasis on memory safety and high performance, Rust presents an attractive option for threat actors seeking to develop efficient and stealthy malware .

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as KrustyLoader .

  • web:blog.eclecticiq.com

    KrustyLoader for Persistence Remote Access EclecticIQ analysts observed the execution of KrustyLoader [3] malware within compromised Ivanti EPMM systems. Threat actors associated with the China-nexus espionage group exploited these systems and utilized publicly accessible Amazon AWS S3 buckets to deliver final payloads.

  • web:labs.withsecure.com

    In such attacks, WithSecure™ detected a threat actor exploiting ScreenConnect and deploying a new Windows variant of the malware dubbed KrustyLoader . KrustyLoader was first named by Synacktiv in January 2024 when analysing implants dropped as part of a widespread campaign targeting the critical vulnerabilities in Ivanti ConnectSecure.

  • web:linuxsecurity.com

    Explore the repercussions of the KrustyLoader malware affecting both Linux and Windows systems, and uncover essential defense measures to safeguard against its threats.

  • web:malpedia.caad.fkie.fraunhofer.de

    KrustyLoader Propose Change ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805. Downloads Sliver backdoor and deletes itself.

  • web:thehackernews.com

    Chinese nation-state hacker group UTA0178 weaponized Ivanti VPN vulnerabilities to deploy the Rust-based KrustyLoader , cryptocurrency miners.

  • web:www.darkreading.com

    Attackers are using a pair of critical zero-day vulnerabilities in Ivanti VPNs to deploy a Rust-based set of backdoors, which in turn download a backdoor malware dubbed " KrustyLoader ."

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.synacktiv.com

    KrustyLoader - as I dubbed it - performs specific checks in order to run only if conditions are met. The fact that KrustyLoader was developed in Rust brings additional difficulties to obtain a good overview of its behaviour. A script as well as a Yara rule are publicly available to help detection and extraction of indicators.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.