s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.kuiper

📛 Threat Title

Malware family: Kuiper

Category: Kuiper First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.kuiper`. Printable name: Kuiper.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.kuiper VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kuiper

IOC database

Type
domain
Value
elf.kuiper
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.kuiper

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kuiper

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Kuiper has exhibited resilience against traditional mitigation strategies, such as backup and restore protocols. Through targeted attacks on backup systems and the deletion of shadow copies, the malware can effectively cripple recovery efforts, leaving victims with limited recourse.

  • web:blog.netmanageit.com

    The Golang-based Kuiper ransomware is presented as an opportunity for other criminals to make money by ransoming one or more targets. Additionally, RobinHood, the actor behind Kuiper , states that help with operations can be provided for a commission.

  • web:hivepro.com

    Kuiper ransomware: Discover its dark origins and RaaS surge. Get a Threat Level Red detailed attack report, mitigation steps, and what's new from Hive Pro.

  • web:stairwell.com

    Technical analysis Kuiper Ransomware is written in Golang and uses a combination of RSA, ChaCha20, and AES for encrypting files. While this ransomware supports Windows, Linux, and OSX systems, functionality related to disabling backups and process termination is primarily designed for Windows-based systems.

  • web:wazuh.com

    In this blog post, we demonstrate how to use Wazuh to detect and remove Kuiper ransomware from an infected Windows endpoint.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.kurtinlaw.com

    FCC Approves Kuiper Systems/Amazon Satellite Constellation Orbital Debris Mitigation Plan On February 8, the Federal Communications Commission ("FCC"), the U.S. satellite regulator, released an Order and Authorization approving Amazon affiliate Kuiper Systems LLC's orbital debris mitigation plan, clearing the way for deployment of Kuiper's Ka-band NGSO (Non-Geostationary Orbit) LEO (Low Earth ...

  • web:www.lexology.com

    Kuiper must also file semi-annual reports on satellite conjunction events, actions taken in response, satellite reentry events, satellite collision avoidance and debris mitigation failures.

  • web:www.pcrisk.com

    What kind of malware is Kuiper ? Our researchers found the Kuiper ransomware during a routine inspection of new submissions to the VirusTotal website. This malicious program is designed to encrypt data and demand ransoms for its decryption. Once we executed a sample of Kuiper on our test system, it began encrypting files.

  • web:www.trellix.com

    Malware changes over time as it evolves due to different wants and needs, and to stay ahead of the competition. While the Kuiper ransomware got many updates over time, not all of which are verifiable, it shows the financial incentive actors have when it comes to ransomware operations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.