s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.disgomoji

📛 Threat Title

Malware family: DISGOMOJI

Category: DISGOMOJI First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.disgomoji`. Printable name: DISGOMOJI.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.disgomoji VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.disgomoji

IOC database

Type
domain
Value
elf.disgomoji
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.disgomoji

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.disgomoji

References (1)

Remediations (10)

  • web:assets.kpmg.com

    DISGOMOJI malware , identified in 2024, is a sophisticated cyber espionage tool associated with the UTA0137 threat actor, believed to operate from Pakistan. Written in Golang for Linux systems, it utilizes Discord for C2 operations, employing emojis for communication. The malware primarily targets government entities, especially in India, aiming to exploit vulnerabilities and maintain ...

  • web:aviatrix.ai

    In 2024, Pakistan's APT group UTA0137 targeted Indian government entities using DISGOMOJI malware , leveraging Discord and emojis for command-and-control communications.

  • web:blog.netmanageit.com

    The campaign leveraged the DISGOMOJI malware , a Golang-based Linux trojan that uses Discord for command and control via emojis. Key capabilities include data exfiltration, persistence mechanisms, and the ability to execute arbitrary commands.

  • web:gurucul.com

    Here's a deep-dive from Gurucul Threat Research Labs on the DisGoMoji Malware , which operates under the control of its creators through the popular messaging platform Discord.

  • web:linuxsecurity.com

    While traditional malware relies on textual-based command and control (C2) mechanisms, DISGOMOJI's use of emoticons for command transmission through Discord is both novel and alarming - bypassing security systems designed to monitor more conventional indicators of compromise thereby creating new difficulties for detection and mitigation .

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the DISGOMOJI malware family including references, samples and yara signatures.

  • web:thehackernews.com

    A suspected Pakistan-based threat actor has been linked to a cyber espionage campaign targeting Indian government entities in 2024. Cybersecurity company Volexity is tracking the activity under the moniker UTA0137, noting the adversary's exclusive use of a malware called DISGOMOJI that's written in ...

  • web:www.cyberstash.com

    Mitigation Defending against the 'DISGOMOJI' Malware Campaign necessitates more than just patching vul-nerabilities. It involves actively limiting and monitoring adversary behaviours and conducting fo-rensic-level post-breach analysis:

  • web:www.rivitmedia.com

    Disgomoji malware has emerged as a significant threat. This malicious software poses a serious risk to both individual users and organizations, compromising data security and system integrity. Understanding the nature of Disgomoji , its actions, and the steps necessary to mitigate its impact is crucial for maintaining robust cybersecurity defenses.ContentsActions and Consequences of Disgomoji ...

  • web:www.volexity.com

    The malware used in these recent campaigns, which Volexity tracks as DISGOMOJI , is written in Golang and compiled for Linux systems. Volexity assesses with high confidence that UTA0137 has espionage-related objectives and a remit to target government entities in India.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.