TF-MAL-osx.kuiper
📛 Threat Title
Malware family: Kuiper
Description
ThreatFox malware family `osx.kuiper`. Printable name: Kuiper.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.kuiper
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.kuiper
IOC database
- Type
- domain
- Value
osx.kuiper- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.kuiper
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.kuiper
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Kuiper has exhibited resilience against traditional mitigation strategies, such as backup and restore protocols. Through targeted attacks on backup systems and the deletion of shadow copies, the malware can effectively cripple recovery efforts, leaving victims with limited recourse.
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Kuiper .
-
web:blog.netmanageit.com
The Golang-based Kuiper ransomware is presented as an opportunity for other criminals to make money by ransoming one or more targets. Additionally, RobinHood, the actor behind Kuiper , states that help with operations can be provided for a commission.
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities. In 2025 alone, security researchers detected ...
-
web:hivepro.com
Kuiper ransomware: Discover its dark origins and RaaS surge. Get a Threat Level Red detailed attack report, mitigation steps, and what's new from Hive Pro.
-
web:intel.dev.threatlabs.protect.jamfcloud.com
Kuiper is a Ransomware-as-a-Service (RaaS) developed in Go, which was advertised on underground forums by a user named Robinhood. It uses a combination of RSA, ChaCha20 (files smaller than 600 megabytes), and AES (files larger than 600 megabytes) for encrypting files. While most of the malware's functionality is focused on Windows, the macOS variant will generate a random key and random ...
-
web:stairwell.com
Technical analysis Kuiper Ransomware is written in Golang and uses a combination of RSA, ChaCha20, and AES for encrypting files. While this ransomware supports Windows, Linux, and OSX systems, functionality related to disabling backups and process termination is primarily designed for Windows-based systems.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.lexology.com
Kuiper must also file semi-annual reports on satellite conjunction events, actions taken in response, satellite reentry events, satellite collision avoidance and debris mitigation failures.
-
web:www.pcrisk.com
What kind of malware is Kuiper ? Our researchers found the Kuiper ransomware during a routine inspection of new submissions to the VirusTotal website. This malicious program is designed to encrypt data and demand ransoms for its decryption. Once we executed a sample of Kuiper on our test system, it began encrypting files.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.