s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.bvp47

📛 Threat Title

Malware family: Bvp47

Category: Bvp47 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.bvp47`. Printable name: Bvp47.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:alpha-cyber.com

    The Bvp47 backdoor, dubbed the "God of Espionage," is a top-tier Linux malware platform attributed to the Equation Group, with strong ties to the US NSA. This advanced persistent threat (APT) tool has enabled covert, long-term control over high-value targets worldwide—including governments, telecoms, energy, and financial sectors—while ...

  • web:gbhackers.com

    Malware authors quickly recognized eBPF's potential, with the Bvp47 backdoor emerging in 2015, followed by rootkits like Ebpfkit and TripleCross. However, the technical complexity required to weaponize eBPF has kept such malware relatively rare.

  • web:linuxsecurity.com

    Instead, security admins should implement tools that analyze network traffic on deeper levels to detect abnormal patterns indicative of potential BPF activity. Regular system patches and updates are another key mitigation strategy against BPFDoor malware , although its presence might linger despite updates to your systems.

  • web:malwaretips.com

    A report released today dives deep into technical aspects of a Linux backdoor now tracked as Bvp47 that is linked to the Equation Group, the advanced persistent threat actor tied to the U.S. National Security Agency. Bvp47 survived until today almost undetected, despite being submitted to the Virus Total antivirus database for the first time close to a decade ago, in late 2013. Until this ...

  • web:min.news

    Equation Group's malware toolset became public knowledge in 2016, when a group calling itself Shadow Brokers leaked a whole batch of exploits used by elite hacking teams, and Kaspersky discovered stolen files used by identified threat actors code-level similarity between samples. Bvp47 as a covert backdoor

  • web:thehackernews.com

    Explore the latest news, real-world incidents, expert analysis, and trends in Bvp47 — only on The Hacker News, the leading cybersecurity and IT news platform.

  • web:thrive.trellix.com

    The backdoor, tracked as Bvp47 , is activated when the threat actor sends a "knock request" to the targeted public-facing server to initiate the connection. Once compromised, the internal servers make an additional connection to another targeted machine via SMB to run command operations on the second server.

  • web:www.bleepingcomputer.com

    Costin Raiu, director of Global Research and Analysis Team at Kaspersky, told BleepingComputer that Bvp47's code-level similarities match a single sample in the company's current malware ...

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.privacy.com.sg

    In the case of the Bvp47 Linux backdoor, Pangu Lab researchers say that it was used on targets in the telecom, military, higher-education, economic, and science sectors. They note that the malware hit more than 287 organizations in 45 countries and went largely undetected for over 10 years.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.