TF-MAL-elf.kuiper
📛 Threat Title
Malware family: Kuiper
Description
ThreatFox malware family `elf.kuiper`. Printable name: Kuiper.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.kuiper
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kuiper
IOC database
- Type
- domain
- Value
elf.kuiper- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.kuiper
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kuiper
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Kuiper has exhibited resilience against traditional mitigation strategies, such as backup and restore protocols. Through targeted attacks on backup systems and the deletion of shadow copies, the malware can effectively cripple recovery efforts, leaving victims with limited recourse.
-
web:blog.netmanageit.com
The Golang-based Kuiper ransomware is presented as an opportunity for other criminals to make money by ransoming one or more targets. Additionally, RobinHood, the actor behind Kuiper , states that help with operations can be provided for a commission.
-
web:hivepro.com
Kuiper ransomware: Discover its dark origins and RaaS surge. Get a Threat Level Red detailed attack report, mitigation steps, and what's new from Hive Pro.
-
web:stairwell.com
Technical analysis Kuiper Ransomware is written in Golang and uses a combination of RSA, ChaCha20, and AES for encrypting files. While this ransomware supports Windows, Linux, and OSX systems, functionality related to disabling backups and process termination is primarily designed for Windows-based systems.
-
web:wazuh.com
In this blog post, we demonstrate how to use Wazuh to detect and remove Kuiper ransomware from an infected Windows endpoint.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.kurtinlaw.com
FCC Approves Kuiper Systems/Amazon Satellite Constellation Orbital Debris Mitigation Plan On February 8, the Federal Communications Commission ("FCC"), the U.S. satellite regulator, released an Order and Authorization approving Amazon affiliate Kuiper Systems LLC's orbital debris mitigation plan, clearing the way for deployment of Kuiper's Ka-band NGSO (Non-Geostationary Orbit) LEO (Low Earth ...
-
web:www.lexology.com
Kuiper must also file semi-annual reports on satellite conjunction events, actions taken in response, satellite reentry events, satellite collision avoidance and debris mitigation failures.
-
web:www.pcrisk.com
What kind of malware is Kuiper ? Our researchers found the Kuiper ransomware during a routine inspection of new submissions to the VirusTotal website. This malicious program is designed to encrypt data and demand ransoms for its decryption. Once we executed a sample of Kuiper on our test system, it began encrypting files.
-
web:www.trellix.com
Malware changes over time as it evolves due to different wants and needs, and to stay ahead of the competition. While the Kuiper ransomware got many updates over time, not all of which are verifiable, it shows the financial incentive actors have when it comes to ransomware operations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.