TF-MAL-elf.soxagent
📛 Threat Title
Malware family: SoxAgent
Description
ThreatFox malware family `elf.soxagent`. Printable name: SoxAgent.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
According to court documents, experts recommend mitigation steps to prevent networks from being recruited into SocksEscort proxy botnets. Regularly update router firmware to patch newly discovered vulnerabilities. Change all default administrative passwords to strong, unique credentials.
-
web:hunt.io
Discover detailed profiles of malware families, including threat actor data, mitigation strategies, and targeted industries to enhance your defenses.
-
web:kpmg.com
Sending reminders to control owners with outstanding remediation plans and, based on the response received, the agent performs preliminary review of evidence of the remediation to determine the likelihood that the issue has been satisfactorily resolved.
-
web:learn.microsoft.com
Find Microsoft's detection name for a malware family in Defender for Endpoint. Learn how Microsoft malware naming works and how to look up the corresponding detection name.
-
web:malpedia.caad.fkie.fraunhofer.de
SLIME88 (Back to overview) SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices and establishing an ORB network tracked as GOBLIN14. The group has targeted IT and manufacturing entities in the US, South Korea, India, and France.
-
web:malpedia.caad.fkie.fraunhofer.de
According to TeamT5, SoxAgent is a Linux backdoor that covertly converts compromised hosts into SOCKS5 relay nodes. It maintains a persistent reverse connection to a hardcoded C2 and negotiates AES-encrypted tunnels, enabling the attacker to forward TCP traffic through the victim to conceal their origin. It supports remote updates, self-deletion, and heartbeat reporting with falsified tunnel ...
-
web:teamt5.org
Based on our investigation and current exploitation status of CVE-2026-34197, we depicted the Forensic Artifacts in this report and prepared a comprehensive Mitigation and Response Advisory for our customers. The Mitigation and Response Advisory includes: - Official Information - Related Indicators of Compromise of this vulnerability.
-
web:undercodetesting.com
Introduction The SmartApeSG campaign represents a sophisticated evolution in malware distribution, leveraging the increasingly prevalent ClickFix social engineering technique to deliver not just one, but a cascade of Remote Access Trojans (RATs) and information stealers. This multi-stage attack, recently analyzed by the SANS Internet Storm Center, demonstrates how threat actors are combining ...
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.