TF-MAL-elf.kaiten
📛 Threat Title
Malware family: Kaiten
Description
ThreatFox malware family `elf.kaiten`. Printable name: Kaiten. Aliases: STD.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.kaiten
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kaiten
IOC database
- Type
- domain
- Value
elf.kaiten- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.kaiten
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kaiten
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:candid.technology
There has been a significant uptick in the activity of two distinct botnets — the Mirai variant 'Ficora' and the Kaiten variant 'Capsaicin' — over October and November 2024. Both botnets leverage long-documented vulnerabilities in D-Link devices, which allow attackers to execute ...
-
web:cybersecsentinel.com
Malware Used: Mirai Variant "FICORA", Kaiten Variant "CAPSAICIN" Threat Score: High (8.7/10) - Due to the exploitation of widely deployed IoT devices and the potential for large-scale Distributed Denial of Service (DDoS) attacks.
-
web:hunt.io
Discover Kaiten , a stealthy malware family enabling remote control and data exfiltration in targeted sectors. Learn about its evolution, tactics, and mitigation strategies.
-
web:informationsecuritybuzz.com
ESET researchers have spotted a new and improved version of Kaiten , an Internet Relay Chat (IRC)-controlled malware typically used to carry out distributed denial-of-service (DDoS) attacks. The remastered malware has been dubbed "KTN-Remastered" or "KTN-RM", with three versions of Linux/Remaiten already identified by ESET researchers. Based on artifacts in the code, the main feature of ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other malicious activities. The trojan does not create any copies of itself. This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
-
web:sechub.in
The malware's configuration, including its C2 server domain and a unique string, is encrypted using the ChaCha20 algorithm. The scanner used by the FICORA botnet includes a hard-coded username and password for its brute force attack function.
-
web:securityaffairs.com
The "CAPSAICIN" malware appears to be a variant of the Keksec group's botnets, likely developed from version 17.0.0 of their malware , based on hard-coded information found within it. "Although the weaknesses exploited in this attack had been exposed and patched nearly a decade ago, these attacks have remained continuously active worldwide.
-
web:thehackernews.com
D-Link vulnerabilities power Mirai and Kaiten botnets, spreading globally. CAPSAICIN botnet targets East Asia with intense malware activity in October
-
web:www.eset.com
Kaiten Returns More Powerful Than Before ESET researchers have spotted a new and improved version of Kaiten , an Internet Relay Chat (IRC)-controlled malware typically used to carry out distributed denial-of-service (DDoS) attacks.
-
web:www.trendmicro.com
In addition, recent variants of Kaiten can kill competing malware , allowing it to fully monopolize a device. Qbot Also known as Bashlite, Gafgyt, Lizkebab, and Torlus, Qbot is also a relatively old malware family , but it remains significant for botnet developers. What is most notable about Qbot is that its source code is made up of only a few ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.