s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.kaiten

📛 Threat Title

Malware family: Kaiten

Category: Kaiten First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.kaiten`. Printable name: Kaiten. Aliases: STD.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.kaiten VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kaiten

IOC database

Type
domain
Value
elf.kaiten
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.kaiten

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kaiten

References (1)

Remediations (10)

  • web:candid.technology

    There has been a significant uptick in the activity of two distinct botnets — the Mirai variant 'Ficora' and the Kaiten variant 'Capsaicin' — over October and November 2024. Both botnets leverage long-documented vulnerabilities in D-Link devices, which allow attackers to execute ...

  • web:cybersecsentinel.com

    Malware Used: Mirai Variant "FICORA", Kaiten Variant "CAPSAICIN" Threat Score: High (8.7/10) - Due to the exploitation of widely deployed IoT devices and the potential for large-scale Distributed Denial of Service (DDoS) attacks.

  • web:hunt.io

    Discover Kaiten , a stealthy malware family enabling remote control and data exfiltration in targeted sectors. Learn about its evolution, tactics, and mitigation strategies.

  • web:informationsecuritybuzz.com

    ESET researchers have spotted a new and improved version of Kaiten , an Internet Relay Chat (IRC)-controlled malware typically used to carry out distributed denial-of-service (DDoS) attacks. The remastered malware has been dubbed "KTN-Remastered" or "KTN-RM", with three versions of Linux/Remaiten already identified by ESET researchers. Based on artifacts in the code, the main feature of ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other malicious activities. The trojan does not create any copies of itself. This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  • web:sechub.in

    The malware's configuration, including its C2 server domain and a unique string, is encrypted using the ChaCha20 algorithm. The scanner used by the FICORA botnet includes a hard-coded username and password for its brute force attack function.

  • web:securityaffairs.com

    The "CAPSAICIN" malware appears to be a variant of the Keksec group's botnets, likely developed from version 17.0.0 of their malware , based on hard-coded information found within it. "Although the weaknesses exploited in this attack had been exposed and patched nearly a decade ago, these attacks have remained continuously active worldwide.

  • web:thehackernews.com

    D-Link vulnerabilities power Mirai and Kaiten botnets, spreading globally. CAPSAICIN botnet targets East Asia with intense malware activity in October

  • web:www.eset.com

    Kaiten Returns More Powerful Than Before ESET researchers have spotted a new and improved version of Kaiten , an Internet Relay Chat (IRC)-controlled malware typically used to carry out distributed denial-of-service (DDoS) attacks.

  • web:www.trendmicro.com

    In addition, recent variants of Kaiten can kill competing malware , allowing it to fully monopolize a device. Qbot Also known as Bashlite, Gafgyt, Lizkebab, and Torlus, Qbot is also a relatively old malware family , but it remains significant for botnet developers. What is most notable about Qbot is that its source code is made up of only a few ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.