TF-MAL-elf.tinyshell
📛 Threat Title
Malware family: TINYSHELL
Description
ThreatFox malware family `elf.tinyshell`. Printable name: TINYSHELL.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.tinyshell
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.tinyshell
IOC database
- Type
- domain
- Value
elf.tinyshell- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.tinyshell
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.tinyshell
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
The RedPenguin project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. RedPenguin activity was separately attributed to UNC3886 and included the deployment of multiple custom versions of the publicly-available TINYSHELL backdoor on Juniper routers.
-
web:bazaar.abuse.ch
Malware samples associated with tag TinyShell MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with TinyShell . Database Entry
-
web:cloud.google.com
Malware Overview Mandiant's investigation identified six distinct malware samples across multiple Juniper MX routers. Each sample is a modified version of a TINYSHELL backdoor, but with unique capabilities.
-
web:gbhackers.com
Mandiant's investigation identified six distinct malware samples across multiple compromised Juniper MX routers. Each sample was a modified version of a TINYSHELL backdoor - a lightweight backdoor written in C that communicates using a custom binary protocol - but with unique capabilities specifically designed for Junos OS.
-
web:sect.iij.ad.jp
In June 2025, we discovered the dropper of new TINYSHELL based Linux malware . Because this malware had code overlapping with PITHOOK, reported to be used by UNC5325, we are confident that this malware is related to attack campaign of UNC5325. UNC5325 is suspected to be China-nexus espionage actor, whose reported to be exploiting vulnerability of Ivanti Connect Secure (CVE-2024-21893) in the ...
-
web:thehackernews.com
UNC3886 exploits Juniper routers with six TinyShell -based backdoors, evading detection and maintaining persistence.
-
web:www.csoonline.com
The threat group UNC3886 uses stolen credentials and custom malware implants to compromise end-of-life routers from Juniper Networks still in use by enterprises and ISPs.
-
web:www.infosecurity-magazine.com
The researchers identified six distinct malware samples across multiple Juniper routers, each of which was a modified version of a Tinyshell backdoor. TinyShell is an open-source backdoor written in C that communicates using a custom binary protocol. The deployed TinyShell -based backdoors had varying custom capabilities.
-
web:www.trendmicro.com
The group's use of TinyShell , Reptile, and Medusa are indicative of its advanced capabilities, showcasing their ability to develop and deploy sophisticated tools tailored for Linux environments. Trend™ Research analyzed and revisited the malware and rootkits used by the group, to get a better understanding of how they operate. TinyShell
-
web:www.vcindi.com
Identified Malware Variants Mandiant has documented six distinct TinyShell -based backdoors deployed by UNC3886: appid (A Poorly Plagiarized Implant Daemon): Enables file transfers, interactive shell access, SOCKS proxy usage, and configuration modifications.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.