s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-osx.uroburos

📛 Threat Title

Malware family: Uroburos

Category: Uroburos First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.uroburos`. Printable name: Uroburos.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.uroburos VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/osx.uroburos (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

IOC database

Type
domain
Value
osx.uroburos
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.uroburos

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/osx.uroburos (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

References (1)

Remediations (10)

  • web:attack.mitre.org

    Uroburos Uroburos is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Security Service (FSB) associated with the Turla toolset to collect intelligence on sensitive targets worldwide.

  • web:cyber-kill-chain.ch

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/ Uroburos . Retrieved December 11, 2014.

  • web:cyberpress.org

    Initial static analysis indicates Uroboros is not just ordinary malware -it represents a feat of both engineering and subversive thinking. Turla's approach incorporates a multi-stage execution chain that moves seamlessly from user-mode to kernel-mode, reflecting a mastery of operating system architecture.

  • web:grokipedia.com

    Turla, also known as Snake or Uroburos , is a modular rootkit and backdoor malware family designed for long-term cyber-espionage, featuring advanced persistence mechanisms and evasion techniques to maintain undetected access in victim networks. Employed by threat actors attributed to Russia's Federal Security Service (FSB), it targets sensitive data exfiltration from high-value entities such as ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Uroburos is a driver for Windows, including a bypass of PatchGuard. According to Andrzej Dereszowski and Matthieu Kaczmarek, "the techniques used demonstrate [their] excellent knowledge of Windows kernel internals."

  • web:misp-galaxy.org

    Uroburos has interoperable implants for Windows, Linux, and macOS, employs a high level of stealth in communications and architecture, and can easily incorporate new or replacement components. (Citation: Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023) (Citation: Kaspersky Turla)

  • web:www.cisa.gov

    The name Uroburos is appropriate, as the FSB cycled it through nearly constant stages of upgrade and redevelopment, even after public disclosures, instead of abandoning it.

  • web:www.huntress.com

    Snake malware , also known as Uroburos , is a highly sophisticated cyber-espionage tool attributed to Advanced Persistent Threat (APT) actors. Primarily classified as a modular rootkit, Snake malware is designed to infiltrate systems, covertly exfiltrate sensitive data, and evade detection. It is notorious for its advanced encryption and stealth tactics, making it a difficult threat to detect ...

  • web:www.linkedin.com

    Initial static analysis indicates Uroboros is not just ordinary malware -it represents a feat of both engineering and subversive thinking.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.