TF-MAL-elf.keyplug
📛 Threat Title
Malware family: KEYPLUG
Description
ThreatFox malware family `elf.keyplug`. Printable name: KEYPLUG. Aliases: ELFSHELF.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.keyplug
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.keyplug
IOC database
- Type
- domain
- Value
elf.keyplug- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.keyplug
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.keyplug
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
KEYPLUG is a modular backdoor written in C++, with Windows and Linux variants, that has been used by APT41 since at least June 2021. [1]
-
web:bazaar.abuse.ch
Malware samples associated with tag keyplug MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with keyplug . Database Entry
-
web:cloud.google.com
Notably, APT41 deployed a new variant of the KEYPLUG backdoor on Linux servers at multiple victims, a malware sub- family we now track as KEYPLUG .LINUX. KEYPLUG is a modular backdoor written in C++ that supports multiple network protocols for command and control (C2) traffic including HTTP, TCP, KCP over UDP, and WSS.
-
web:cybersecsentinel.com
Conclusion APT41's continued exploitation of edge infrastructure vulnerabilities, including in Fortinet products, demands immediate remediation . Although a direct chain from Fortinet flaws to KEYPLUG deployment is not validated, the components involved each represent serious threats.
-
web:cybersecuritynews.com
A server tied to KeyPlug malware exposed hacking tools crafted to exploit Fortinet firewall and VPN vulnerabilities.
-
web:hunt.io
KeyPlug is a modular backdoor malware from APT41 (Grayfly) that targets Windows and Linux systems. It gives attackers full control over compromised devices. KeyPlug has been used in espionage since at least June 2021.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the KEYPLUG malware family including references, samples and yara signatures.
-
web:rewterz.com
Remediation Block all threat indicators at your respective controls. Search for indicators of compromise (IOCs) in your environment utilizing your respective security controls. Immediately patch all Fortinet devices to address CVE-2024-23108 and CVE-2024-23109 vulnerabilities. Monitor network traffic for suspicious or unauthorized WebSocket handshake requests, especially targeting FortiOS ...
-
web:www.csa.gov.sg
Security researchers have identified a cluster of new infrastructure associated with the custom Windows and Linux backdoor malware KEYPLUG . The KEYPLUG malware is reportedly being used to target organisations in various sectors. A malware with a backdoor capability is able to bypass normal authentication procedures and gain access to a system. Once the malware is installed, it provides ...
-
web:www.tinextacyber.com
The group's tactics, techniques, and procedures (TTPs) include the deployment of malware , phishing, exploitation of zero-day software vulnerabilities, and supply chain attacks. Their activities pose a global threat, necessitating constant vigilance from cybersecurity professionals to mitigate associated risks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.