TF-MAL-elf.unidentified_006
📛 Threat Title
Malware family: Unidentified ELF 006 (Tox Backdoor)
Description
ThreatFox malware family `elf.unidentified_006`. Printable name: Unidentified ELF 006 (Tox Backdoor).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls ...
-
web:bazaar.abuse.ch
Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with elf .
-
web:carthageelectronics.com
Critical zero-day vulnerabilities in May 2026: cPanel CVE-2026-41940, Windows APT28 NTLM exploit, Chrome, Cisco, VMware, CISA KEV updates and full remediation guidance.
-
web:cyberwebspider.com
Silver Fox uses fraudulent tax emails to spread malware . Learn how to protect your organization from this sophisticated threat.
-
web:github.com
This repository contains relevant samples and data related to the ELF Malware Analysis 101 articles - intezer/ ELF - Malware -Analysis-101
-
web:learn.microsoft.com
When you look up this malware name in the Microsoft Defender Security Intelligence website, you find information specific to that malware , including technical details and mitigation steps.
-
web:malpedia.caad.fkie.fraunhofer.de
Unidentified ELF 006 (Tox Backdoor) Propose Change Enables remote execution of scripts on a host, communicates via Tox .
-
web:media.defense.gov
Malware Summary BRICKSTORM is a custom Executable and Linkable Format ( ELF ) Go- or Rust-based backdoor (eight originally analyzed samples are Go-based, and two of the three new samples in the Dec. 19, 2025, update are Rust-based).
-
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.How to use the KEV ...
-
web:www.cve.org
Identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There are currently over 334,000 CVE Records accessible via Download or Keyword Search above.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.