TF-MAL-elf.krustyloader
📛 Threat Title
Malware family: KrustyLoader
Description
ThreatFox malware family `elf.krustyloader`. Printable name: KrustyLoader.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.krustyloader
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.krustyloader
IOC database
- Type
- domain
- Value
elf.krustyloader- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.krustyloader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.krustyloader
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The emergence of a new threat in the form of KrustyLoader , a Rust-based backdoor actively targeting both Windows and Linux operating systems. With its emphasis on memory safety and high performance, Rust presents an attractive option for threat actors seeking to develop efficient and stealthy malware .
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as KrustyLoader .
-
web:blog.eclecticiq.com
KrustyLoader for Persistence Remote Access EclecticIQ analysts observed the execution of KrustyLoader [3] malware within compromised Ivanti EPMM systems. Threat actors associated with the China-nexus espionage group exploited these systems and utilized publicly accessible Amazon AWS S3 buckets to deliver final payloads.
-
web:labs.withsecure.com
In such attacks, WithSecure™ detected a threat actor exploiting ScreenConnect and deploying a new Windows variant of the malware dubbed KrustyLoader . KrustyLoader was first named by Synacktiv in January 2024 when analysing implants dropped as part of a widespread campaign targeting the critical vulnerabilities in Ivanti ConnectSecure.
-
web:linuxsecurity.com
Explore the repercussions of the KrustyLoader malware affecting both Linux and Windows systems, and uncover essential defense measures to safeguard against its threats.
-
web:malpedia.caad.fkie.fraunhofer.de
KrustyLoader Propose Change ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805. Downloads Sliver backdoor and deletes itself.
-
web:thehackernews.com
Chinese nation-state hacker group UTA0178 weaponized Ivanti VPN vulnerabilities to deploy the Rust-based KrustyLoader , cryptocurrency miners.
-
web:www.darkreading.com
Attackers are using a pair of critical zero-day vulnerabilities in Ivanti VPNs to deploy a Rust-based set of backdoors, which in turn download a backdoor malware dubbed " KrustyLoader ."
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.synacktiv.com
KrustyLoader - as I dubbed it - performs specific checks in order to run only if conditions are met. The fact that KrustyLoader was developed in Rust brings additional difficulties to obtain a good overview of its behaviour. A script as well as a Yara rule are publicly available to help detection and extraction of indicators.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.