s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.chalubo

📛 Threat Title

Malware family: Chalubo

Category: Chalubo First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.chalubo`. Printable name: Chalubo. Aliases: ChaChaDDoS.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.chalubo VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.chalubo

IOC database

Type
domain
Value
elf.chalubo
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.chalubo

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.chalubo

References (1)

Remediations (10)

  • web:assets.kpmg.com

    The malware incorporates evasion tactics such as a 30-minute delay upon execution, to thwart sandbox detection and evade automated analysis. Chalubo's targeted approach and specific ASN focus distinguish it from broad attacks on multiple router models and networks, necessitating a strategic and precise countermeasure.

  • web:cyberinsider.com

    The culprit behind this widespread disruption was identified as the Chalubo remote access trojan (RAT), a commodity malware first observed in 2018. Chalubo's advanced obfuscation techniques, including in-memory execution, random process naming, and encrypted communications with command and control (C2) servers, have contributed to its elusiveness.

  • web:cybernews.com

    The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.

  • web:en.linuxadictos.com

    Collection and sending of information: The Chalubo executable collects host information such as MAC address, device ID, software version, and local IP addresses and sends it to an external server. Download and run the Main component: Chalubo checks the availability of the control servers and downloads the main malware component, which is decrypted using the ChaCha20 stream cipher. Running lua ...

  • web:hunt.io

    Chalubo is a remote access trojan (RAT) first identified in 2018, targeting Linux-based systems and IoT devices. It combines elements from Mirai and XorDDoS, enhancing its capabilities to launch distributed denial-of-service (DDoS) attacks. Chalubo distinguishes itself by employing encryption for its communications and using Lua scripts for modular execution. Notably, it has been implicated in ...

  • web:malwaretips.com

    Lumen's global telemetry indicates the Chalubo malware family was highly active in November 2023 and remained so into early 2024. Based on a 30-day snapshot in October, Lumen identified over 330,000 unique IP addresses that communicated with one of 75 observed C2 nodes for at least two days, indicating a confirmed infection.

  • web:www.interest.co.nz

    An information security firm has published details of a large-scale malware attack in October last year that resulted in over 600,000 small and home office (SOHO) gateways being rendered permanently inoperable in just 72 hours, with the devices needing to be physically replaced. Researchers at security vendor Lumen Technologies' Black Lotus Labs said the attack using the 'Chalubo' remote ...

  • web:www.linkedin.com

    Lumen's telemetry data indicated high activity of the Chalubo malware family in November 2023 and early 2024.

  • web:www.mphasis.com

    The threat actor responsible for the attack, Lumen says, likely chose Chalubo to deploy malicious firmware on the impacted routers to obfuscate attribution, but no evidence of overlaps between this incident and known nation-state actors, such as Volt Typhoon, has been found.

  • web:www.techradar.com

    A malicious botnet bricked 600,000 office and home office (SOHO) routers in what seems to be a coordinated attack against a specific internet service provider (ISP).

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.