s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.soxagent

📛 Threat Title

Malware family: SoxAgent

Category: SoxAgent First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.soxagent`. Printable name: SoxAgent.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    According to court documents, experts recommend mitigation steps to prevent networks from being recruited into SocksEscort proxy botnets. Regularly update router firmware to patch newly discovered vulnerabilities. Change all default administrative passwords to strong, unique credentials.

  • web:hunt.io

    Discover detailed profiles of malware families, including threat actor data, mitigation strategies, and targeted industries to enhance your defenses.

  • web:kpmg.com

    Sending reminders to control owners with outstanding remediation plans and, based on the response received, the agent performs preliminary review of evidence of the remediation to determine the likelihood that the issue has been satisfactorily resolved.

  • web:learn.microsoft.com

    Find Microsoft's detection name for a malware family in Defender for Endpoint. Learn how Microsoft malware naming works and how to look up the corresponding detection name.

  • web:malpedia.caad.fkie.fraunhofer.de

    SLIME88 (Back to overview) SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices and establishing an ORB network tracked as GOBLIN14. The group has targeted IT and manufacturing entities in the US, South Korea, India, and France.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to TeamT5, SoxAgent is a Linux backdoor that covertly converts compromised hosts into SOCKS5 relay nodes. It maintains a persistent reverse connection to a hardcoded C2 and negotiates AES-encrypted tunnels, enabling the attacker to forward TCP traffic through the victim to conceal their origin. It supports remote updates, self-deletion, and heartbeat reporting with falsified tunnel ...

  • web:teamt5.org

    Based on our investigation and current exploitation status of CVE-2026-34197, we depicted the Forensic Artifacts in this report and prepared a comprehensive Mitigation and Response Advisory for our customers. The Mitigation and Response Advisory includes: - Official Information - Related Indicators of Compromise of this vulnerability.

  • web:undercodetesting.com

    Introduction The SmartApeSG campaign represents a sophisticated evolution in malware distribution, leveraging the increasingly prevalent ClickFix social engineering technique to deliver not just one, but a cascade of Remote Access Trojans (RATs) and information stealers. This multi-stage attack, recently analyzed by the SANS Internet Storm Center, demonstrates how threat actors are combining ...

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.