s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.sysjoker

📛 Threat Title

Malware family: SysJoker

Category: SysJoker First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.sysjoker`. Printable name: SysJoker.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.sysjoker VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.sysjoker

IOC database

Type
domain
Value
osx.sysjoker
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.sysjoker

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.sysjoker

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    Malware samples associated with tag SysJoker MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with SysJoker . Database Entry

  • web:blogs.vmware.com

    SysJoker RAT is cross-platform malware which targets Windows, Linux and macOS operating systems. Being cross-platform allows the malware authors to gain advantage of wide infection on all major platforms. SysJoker has the ability to execute commands remotely as well as download and execute new malware on victim machines.

  • web:hackread.com

    The report offers in-depth insights on the Rust variant of SysJoker and its Windows variants with their attributions along with infection vectors, the C2 communication mechanism, and malware's functionalities, which include downloading/uploading files, executing commands, and capturing screenshots.

  • web:link.springer.com

    In the paper, we provide a feasibility study of the proposed solution based on the ATT &CK MITRE exploit attack graph emulation of the SysJoker backdoor malware and we train several Deep Learning models acting as classifiers.

  • web:malpedia.caad.fkie.fraunhofer.de

    Sysjoker is a backdoor malware that was first discovered in December 2021 by Intezer. It is sophisticated and written from scratch in C++. Sysjoker is a cross-platform malware that has Linux, Windows, and macOS variants. Possible attack vectors for Sysjoker are email attachments, malicious advertisements, and trojanized software.

  • web:objective-see.org

    " SysJoker was first discovered during an active attack on a Linux-based web server of a leading educational institution. After further investigation, we found that SysJoker also has Mach-O and Windows PE versions.

  • web:thrive.trellix.com

    The SysJoker backdoor was discovered in 2021 and targets Windows, Linux, and macOS systems. The multi-platform malware is written in C++ and reaches out to a hardcoded Google Drive link for a list of current command-and-control servers.

  • web:www.broadcom.com

    An APT campaign was reported to be associated with Hamas-linked threat actors utilizing a new multi-platform Rust-based malware dubbed 'SysJoker' . The new variant, although rewritten from its former C++ based code, maintains its original functionality such as collection of victims' computer information including OS version and MAC address among ...

  • web:www.pcrisk.com

    SysJoker was first discovered by Intezer in January 2022, with researchers describing the malware as follows, SysJoker was first discovered during an active attack on a Linux-based web server of a leading educational institution. After further investigation, we found that SysJoker also has Mach-O and Windows PE versions.

  • web:www.securityweek.com

    Malware & Threats New Cross-Platform Backdoor 'SysJoker' Used in Targeted Attacks A backdoor likely used by an advanced persistent threat (APT) actor in targeted attacks was built to target Windows, macOS, and Linux systems, Intezer reports.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.