s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.kitty_soks5

📛 Threat Title

Malware family: kitty-socks5

Category: kitty-socks5 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.kitty_soks5`. Printable name: kitty-socks5.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:accuknox.com

    The SOCKS5 proxy handshake problem Attackers exploit CVE-2023-38545 by manipulating how cURL communicates with a SOCKS5 proxy. During the connection process, attackers can send specially crafted data that causes cURL to handle memory incorrectly. SOCKS5 is a protocol that routes network traffic through a proxy server.

  • web:cybersecuritynews.com

    A new malware strain dubbed GhostSocks is leveraging SOCKS5 backconnect proxies to bypass anti-fraud mechanisms and geographic restrictions, according to a report by cybersecurity firm Infrawatch. The Golang-based malware , first advertised on Russian-language forums in October 2023, has recently expanded to English-speaking cybercriminal communities, offering attackers a streamlined method to ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the kitty-socks5 malware family including references, samples and yara signatures.

  • web:redskyalliance.org

    The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a joint cyber security advisory on the growing threat of Ghost ransomware. A variation of this strain of malware called GhostSocks uses SOCKS5 to bypass anti-fraud mechanisms and geographic restrictions. First detected in 2021, this ransomware group has targeted organizations in over 70 countries, exploiting ...

  • web:rewterz.com

    47cd550be7567b8ff091fff32cd0d7c3c0e4f7d2 Remediation Block all threat indicators at your respective controls. Search for indicators of compromise (IOCs) in your environment utilizing your respective security controls. Disconnect infected devices from the internet and local networks immediately to prevent the ransomware from spreading.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.fortinet.com

    An in-depth analysis of an Interlock ransomware intrusion, detailing new malware tooling, defense evasion techniques, and high-ROI detection strategies.

  • web:www.huntress.com

    CVE-2023-38545, also known as " SOCKS5 heap buffer overflow," is a high-severity vulnerability in the widely used cURL library. This flaw allows a malicious server to trigger a buffer overflow in a connecting client, potentially leading to remote code execution (RCE). It affects applications that use libcurl for SOCKS5 proxy handshakes.

  • web:www.king.net

    The latest example is a new Chaos malware variant that specifically targets cloud misconfigurations and leverages a SOCKS proxy to evade detection. In this blog post, we will dive into how this emerging threat operates, why it's so dangerous for cloud environments, and what security teams can do to protect their infrastructure from exploitation.

  • web:www.wiz.io

    Understand the critical aspects of CVE-2023-38545 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.