s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.bella

📛 Threat Title

Malware family: Bella

Category: Bella First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.bella`. Printable name: Bella.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.bella VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.bella

IOC database

Type
domain
Value
osx.bella
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.bella

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.bella

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    EXECUTIVE SUMMARY The BellaCiao malware family exemplifies a unique blend of persistence and stealth, as demonstrated through its evolution from .NET to C++ implementations. Initially surfacing in early spring, the malware's distinguishing features include a sophisticated versioning system identifiable through descriptive PDB paths. These paths not only reveal insights into campaign details ...

  • web:assets.adgm.com

    Microsoft Exchange The C++ Server in engineering documented in BellaCiao is a custom dropper malware vulnerabilities and India. BellaCPP: payloads (e.g., "D3D12_1core.dll") for creating similar functionality in applications web shell feature that to of BellaCiao, ManageEngine malware , identified including to as establish unauthorized ("adhapl.dll"), to additional Threat malware leveraging ...

  • web:cyberpress.org

    BellaCiao is a .NET malware family linked to Charming Kitten, which employs webshell-like persistence and covert tunneling capabilities.

  • web:cybersecsentinel.com

    Mitigation and Prevention User Awareness: Conduct regular training to recognize phishing attempts and suspicious activities. Email Filtering: Implement advanced email filtering to detect and block malicious attachments and links. Antivirus Protection: Ensure up-to-date antivirus solutions are in place and regularly scan systems for malware .

  • web:rewterz.com

    A C++ version of the well-known malware BellaCiao has been seen being used by the Iranian nation-state APT group Charming Kitten. Researchers who named the new variant BellaCPP found the artifact as part of a recent investigation into a hacked machine in Asia that was also infected with the malware .

  • web:securelist.com

    While investigating an incident involving the BellaCiao .NET malware , Kaspersky researchers discovered a C++ version they dubbed "BellaCPP".

  • web:securityaffairs.com

    Iran-linked APT group Charming Kitten has been observed using a new variant of the BellaCiao malware dubbed BellaCPP, Kaspersky warns.

  • web:undercodenews.com

    2024-12-23 This article delves into the intricacies of the BellaCiao malware family , a persistent threat linked to the notorious Charming Kitten threat actor group. Through an analysis of a recent intrusion investigation, researchers uncovered a new C++ variant, BellaCPP, operating alongside a pre-existing BellaCiao sample.

  • web:www.cyberstash.com

    BellaCiao is a dropper malware that delivers other malware payloads onto the victim's computer system. The executable is written to specific locations on the system and runs as a service, using names resembling legitimate Microsoft Exchange services.

  • web:www.threatintelreport.com

    The latest findings reveal enhanced capabilities of the malware , including new command-and-control (C2) mechanisms and refined operational tactics. These improvements underscore APT35's commitment to advancing its cyber warfare techniques.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.