s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.tinyshell

📛 Threat Title

Malware family: TINYSHELL

Category: TINYSHELL First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.tinyshell`. Printable name: TINYSHELL.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.tinyshell VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.tinyshell

IOC database

Type
domain
Value
elf.tinyshell
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.tinyshell

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.tinyshell

References (1)

Remediations (10)

  • web:attack.mitre.org

    The RedPenguin project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. RedPenguin activity was separately attributed to UNC3886 and included the deployment of multiple custom versions of the publicly-available TINYSHELL backdoor on Juniper routers.

  • web:bazaar.abuse.ch

    Malware samples associated with tag TinyShell MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with TinyShell . Database Entry

  • web:cloud.google.com

    Malware Overview Mandiant's investigation identified six distinct malware samples across multiple Juniper MX routers. Each sample is a modified version of a TINYSHELL backdoor, but with unique capabilities.

  • web:gbhackers.com

    Mandiant's investigation identified six distinct malware samples across multiple compromised Juniper MX routers. Each sample was a modified version of a TINYSHELL backdoor - a lightweight backdoor written in C that communicates using a custom binary protocol - but with unique capabilities specifically designed for Junos OS.

  • web:sect.iij.ad.jp

    In June 2025, we discovered the dropper of new TINYSHELL based Linux malware . Because this malware had code overlapping with PITHOOK, reported to be used by UNC5325, we are confident that this malware is related to attack campaign of UNC5325. UNC5325 is suspected to be China-nexus espionage actor, whose reported to be exploiting vulnerability of Ivanti Connect Secure (CVE-2024-21893) in the ...

  • web:thehackernews.com

    UNC3886 exploits Juniper routers with six TinyShell -based backdoors, evading detection and maintaining persistence.

  • web:www.csoonline.com

    The threat group UNC3886 uses stolen credentials and custom malware implants to compromise end-of-life routers from Juniper Networks still in use by enterprises and ISPs.

  • web:www.infosecurity-magazine.com

    The researchers identified six distinct malware samples across multiple Juniper routers, each of which was a modified version of a Tinyshell backdoor. TinyShell is an open-source backdoor written in C that communicates using a custom binary protocol. The deployed TinyShell -based backdoors had varying custom capabilities.

  • web:www.trendmicro.com

    The group's use of TinyShell , Reptile, and Medusa are indicative of its advanced capabilities, showcasing their ability to develop and deploy sophisticated tools tailored for Linux environments. Trend™ Research analyzed and revisited the malware and rootkits used by the group, to get a better understanding of how they operate. TinyShell

  • web:www.vcindi.com

    Identified Malware Variants Mandiant has documented six distinct TinyShell -based backdoors deployed by UNC3886: appid (A Poorly Plagiarized Implant Daemon): Enables file transfers, interactive shell access, SOCKS proxy usage, and configuration modifications.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.