s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.poseidon

📛 Threat Title

Malware family: Poseidon

Category: Poseidon First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.poseidon`. Printable name: Poseidon.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.poseidon VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.poseidon

IOC database

Type
domain
Value
elf.poseidon
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.poseidon

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.poseidon

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Poseidon .

  • web:brandefense.io

    Response & Mitigation Tactics From Experts You can reach the exclusive details to produce proactive solutions. The malware campaign has been increasingly active and sophisticated in recent years, making it more difficult for companies to protect themselves.

  • web:cyberpress.org

    Security researcher has documented Operation Poseidon , a sophisticated spear-phishing campaign attributed to the Konni APT group that weaponizes legitimate Google Ads infrastructure to distribute EndRAT malware .

  • web:malpedia.caad.fkie.fraunhofer.de

    DISGOMOJI Poseidon Action RAT AllaKore ReverseRAT 2023-10-15 ⋅ ⋅ Cert-UA ⋅ Cert-UA Peculiarities of destructive cyber attacks against Ukrainian providers (CERT-UA#7627) Poseidon UAC-0006 2023-07-13 ⋅ Brandefense ⋅ Brandefense APT 36 Campaign - Poseidon Malware Technical Analysis Poseidon Crimson RAT Oblique RAT

  • web:redcanary.com

    Without direct access to the malware's command-and-control (C2) infrastructure, distinguishing between Atomic and Poseidon based solely on endpoint telemetry can be a difficult task. The core challenge for defenders has become finding subtle, yet reliable, indicators that can precisely attribute a stealer to a specific family .

  • web:techowlshield.com

    Technical Analysis Poseidon hides itself inside a fake macOS app. It usually comes in a DMG file that looks like a trusted application 'MacAppsLauncher'. When the user opens the DMG file, it extracts a Mach-O file. This file looks like it is part of a normal system update, but in reality, it is the main stealer malware . Once opened, it starts collecting important data from the system like ...

  • web:www.cyfirma.com

    Odyssey Stealer represents the latest evolution in macOS-targeting malware , emerging as a rebranded version of Poseidon Stealer which itself originated as a fork of the AMOS Stealer.

  • web:www.genians.co.kr

    Key Findings A spear phishing campaign disguised as advertising URLs was used to bypass security filtering mechanisms and user awareness Poorly secured WordPress websites were abused as malware distribution points and C2 infrastructure " Poseidon " was identified as an internally named and operated attack operation unit attributed to the Konni APT The EndRAT malware was loaded through the ...

  • web:www.malwarebytes.com

    Info stealers are a type of malware that resides in an infected computer and gathers data in order to send it to the attacker. Protection Malwarebytes for Mac detects and removes OSX. Poseidon . Remediation Malwarebytes for Mac will detect and remove the components of this malware . Download and install the latest version of Malwarebytes for Mac.

  • web:www.ncsc.admin.ch

    11.07.2024 - At the end of June 2024, cybercriminals spread the malware " Poseidon Stealer" in German-speaking Switzerland by email, using AGOV as a lure with the aim of infecting computers with the macOS operating system. The NCSC has now produced and published a brief technical analysis of the malware .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.