s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.ktlv_door

📛 Threat Title

Malware family: KTLVdoor

Category: KTLVdoor First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.ktlv_door`. Printable name: KTLVdoor.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:devp.threatvirus.com

    Malware Analysis Targets Multiple Platforms KTLVDoor is a unique malware strain that can infect systems running Windows, Linux, and macOS. This cross-platform capability allows the malware to spread more widely and target a broader range of users and organizations1. Backdoor Functionality KTLVDoor functions as a backdoor, granting attackers remote access to the compromised systems. Once ...

  • web:hunt.io

    KTLVdoor is a cross-platform backdoor malware written in Golang for Windows and Linux systems. It is highly obfuscated and disguised as legitimate system utilities such as sshd, java, sqlite, bash, and edr-agent. Once dropped, KTLVdoor allows attackers to execute commands, manipulate files and port scan remotely, with full control of the compromised system.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to carry out a variety of tasks including file manipulation, command execution, and remote port scanning.

  • web:thecyberexpress.com

    New KTLVdoor Malware Linked to Chinese Threat Actor Earth Lusca While the researchers tied down the samples of the KTLVdoor malware to Earth Lusca with high confidence in their investigation, they were unable to determine if these servers were exclusive to the group's operations or had also been shared with other cybercriminal groups.

  • web:www.broadcom.com

    A new Golang-based backdoor dubbed KTLVdoor has been discovered by researchers from Trend Micro. The malware has been attributed to the Funnelweb APT (also known as Earth Lusca). KTLVdoor is a highly obfuscated malware that comes in variants supporting both Windows and Linux platforms.

  • web:www.cybermaterial.com

    The discovery of KTLVdoor , a sophisticated backdoor malware developed by the Chinese-speaking threat actor Earth Lusca, marks a significant evolution in the capabilities of cyber adversaries. Written in Golang, KTLVdoor operates across both Microsoft Windows and Linux platforms, showcasing the growing trend of threat actors leveraging multiplatform malware to target a broader range of systems ...

  • web:www.darkreading.com

    China's 'Earth Lusca' Propagates Multiplatform Backdoor The malware , KTLVdoor , has already been found on more than 50 command-and-control servers and enables full control of any environment it ...

  • web:www.imda.gov.sg

    They are known to rely heavily on Cobalt Strike, ShadowPad, Winnti and Spyder malware families. KTLVdoor , the latest addition to the group's malware arsenal, is observed to have more than 50 command and control (C2) servers, all hosted by Chinese ISP Alibaba. With embedded strings that are not directly readable, symbols stripped, and most functions and packages renamed to random Base64-like ...

  • web:www.itscybernews.com

    The Rise of KTLVdoor Malware New KTLVdoor Malware Discovered in Chinese Trading Firm Attack In a recent discovery, cybersecurity researchers have identified a new strain of cross-platform malware known as KTLVdoor . This malware has been linked to an attack on a Chinese trading firm, where it was used to infiltrate both Linux and Windows systems.

  • web:www.trendmicro.com

    We discovered a new multiplatform backdoor written in Golang that we named KTLVdoor while monitoring Earth Lusca, a Chinese-speaking threat actor we had previously covered. Our investigation also uncovered both Microsoft Windows and Linux versions of this new malware family .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.