s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.kuiper

📛 Threat Title

Malware family: Kuiper

Category: Kuiper First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.kuiper`. Printable name: Kuiper.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.kuiper VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.kuiper

IOC database

Type
domain
Value
osx.kuiper
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.kuiper

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.kuiper

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Kuiper has exhibited resilience against traditional mitigation strategies, such as backup and restore protocols. Through targeted attacks on backup systems and the deletion of shadow copies, the malware can effectively cripple recovery efforts, leaving victims with limited recourse.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Kuiper .

  • web:blog.netmanageit.com

    The Golang-based Kuiper ransomware is presented as an opportunity for other criminals to make money by ransoming one or more targets. Additionally, RobinHood, the actor behind Kuiper , states that help with operations can be provided for a commission.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities. In 2025 alone, security researchers detected ...

  • web:hivepro.com

    Kuiper ransomware: Discover its dark origins and RaaS surge. Get a Threat Level Red detailed attack report, mitigation steps, and what's new from Hive Pro.

  • web:intel.dev.threatlabs.protect.jamfcloud.com

    Kuiper is a Ransomware-as-a-Service (RaaS) developed in Go, which was advertised on underground forums by a user named Robinhood. It uses a combination of RSA, ChaCha20 (files smaller than 600 megabytes), and AES (files larger than 600 megabytes) for encrypting files. While most of the malware's functionality is focused on Windows, the macOS variant will generate a random key and random ...

  • web:stairwell.com

    Technical analysis Kuiper Ransomware is written in Golang and uses a combination of RSA, ChaCha20, and AES for encrypting files. While this ransomware supports Windows, Linux, and OSX systems, functionality related to disabling backups and process termination is primarily designed for Windows-based systems.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.lexology.com

    Kuiper must also file semi-annual reports on satellite conjunction events, actions taken in response, satellite reentry events, satellite collision avoidance and debris mitigation failures.

  • web:www.pcrisk.com

    What kind of malware is Kuiper ? Our researchers found the Kuiper ransomware during a routine inspection of new submissions to the VirusTotal website. This malicious program is designed to encrypt data and demand ransoms for its decryption. Once we executed a sample of Kuiper on our test system, it began encrypting files.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.