TF-MAL-elf.chalubo
📛 Threat Title
Malware family: Chalubo
Description
ThreatFox malware family `elf.chalubo`. Printable name: Chalubo. Aliases: ChaChaDDoS.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.chalubo
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.chalubo
IOC database
- Type
- domain
- Value
elf.chalubo- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.chalubo
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.chalubo
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:assets.kpmg.com
The malware incorporates evasion tactics such as a 30-minute delay upon execution, to thwart sandbox detection and evade automated analysis. Chalubo's targeted approach and specific ASN focus distinguish it from broad attacks on multiple router models and networks, necessitating a strategic and precise countermeasure.
-
web:cyberinsider.com
The culprit behind this widespread disruption was identified as the Chalubo remote access trojan (RAT), a commodity malware first observed in 2018. Chalubo's advanced obfuscation techniques, including in-memory execution, random process naming, and encrypted communications with command and control (C2) servers, have contributed to its elusiveness.
-
web:cybernews.com
The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.
-
web:en.linuxadictos.com
Collection and sending of information: The Chalubo executable collects host information such as MAC address, device ID, software version, and local IP addresses and sends it to an external server. Download and run the Main component: Chalubo checks the availability of the control servers and downloads the main malware component, which is decrypted using the ChaCha20 stream cipher. Running lua ...
-
web:hunt.io
Chalubo is a remote access trojan (RAT) first identified in 2018, targeting Linux-based systems and IoT devices. It combines elements from Mirai and XorDDoS, enhancing its capabilities to launch distributed denial-of-service (DDoS) attacks. Chalubo distinguishes itself by employing encryption for its communications and using Lua scripts for modular execution. Notably, it has been implicated in ...
-
web:malwaretips.com
Lumen's global telemetry indicates the Chalubo malware family was highly active in November 2023 and remained so into early 2024. Based on a 30-day snapshot in October, Lumen identified over 330,000 unique IP addresses that communicated with one of 75 observed C2 nodes for at least two days, indicating a confirmed infection.
-
web:www.interest.co.nz
An information security firm has published details of a large-scale malware attack in October last year that resulted in over 600,000 small and home office (SOHO) gateways being rendered permanently inoperable in just 72 hours, with the devices needing to be physically replaced. Researchers at security vendor Lumen Technologies' Black Lotus Labs said the attack using the 'Chalubo' remote ...
-
web:www.linkedin.com
Lumen's telemetry data indicated high activity of the Chalubo malware family in November 2023 and early 2024.
-
web:www.mphasis.com
The threat actor responsible for the attack, Lumen says, likely chose Chalubo to deploy malicious firmware on the impacted routers to obfuscate attribution, but no evidence of overlaps between this incident and known nation-state actors, such as Volt Typhoon, has been found.
-
web:www.techradar.com
A malicious botnet bricked 600,000 office and home office (SOHO) routers in what seems to be a coordinated attack against a specific internet service provider (ISP).
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.