TF-MAL-elf.disgomoji
📛 Threat Title
Malware family: DISGOMOJI
Description
ThreatFox malware family `elf.disgomoji`. Printable name: DISGOMOJI.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.disgomoji
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.disgomoji
IOC database
- Type
- domain
- Value
elf.disgomoji- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.disgomoji
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.disgomoji
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:assets.kpmg.com
DISGOMOJI malware , identified in 2024, is a sophisticated cyber espionage tool associated with the UTA0137 threat actor, believed to operate from Pakistan. Written in Golang for Linux systems, it utilizes Discord for C2 operations, employing emojis for communication. The malware primarily targets government entities, especially in India, aiming to exploit vulnerabilities and maintain ...
-
web:aviatrix.ai
In 2024, Pakistan's APT group UTA0137 targeted Indian government entities using DISGOMOJI malware , leveraging Discord and emojis for command-and-control communications.
-
web:blog.netmanageit.com
The campaign leveraged the DISGOMOJI malware , a Golang-based Linux trojan that uses Discord for command and control via emojis. Key capabilities include data exfiltration, persistence mechanisms, and the ability to execute arbitrary commands.
-
web:gurucul.com
Here's a deep-dive from Gurucul Threat Research Labs on the DisGoMoji Malware , which operates under the control of its creators through the popular messaging platform Discord.
-
web:linuxsecurity.com
While traditional malware relies on textual-based command and control (C2) mechanisms, DISGOMOJI's use of emoticons for command transmission through Discord is both novel and alarming - bypassing security systems designed to monitor more conventional indicators of compromise thereby creating new difficulties for detection and mitigation .
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the DISGOMOJI malware family including references, samples and yara signatures.
-
web:thehackernews.com
A suspected Pakistan-based threat actor has been linked to a cyber espionage campaign targeting Indian government entities in 2024. Cybersecurity company Volexity is tracking the activity under the moniker UTA0137, noting the adversary's exclusive use of a malware called DISGOMOJI that's written in ...
-
web:www.cyberstash.com
Mitigation Defending against the 'DISGOMOJI' Malware Campaign necessitates more than just patching vul-nerabilities. It involves actively limiting and monitoring adversary behaviours and conducting fo-rensic-level post-breach analysis:
-
web:www.rivitmedia.com
Disgomoji malware has emerged as a significant threat. This malicious software poses a serious risk to both individual users and organizations, compromising data security and system integrity. Understanding the nature of Disgomoji , its actions, and the steps necessary to mitigate its impact is crucial for maintaining robust cybersecurity defenses.ContentsActions and Consequences of Disgomoji ...
-
web:www.volexity.com
The malware used in these recent campaigns, which Volexity tracks as DISGOMOJI , is written in Golang and compiled for Linux systems. Volexity assesses with high confidence that UTA0137 has espionage-related objectives and a remit to target government entities in India.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.