TF-MAL-osx.bella
📛 Threat Title
Malware family: Bella
Description
ThreatFox malware family `osx.bella`. Printable name: Bella.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.bella
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.bella
IOC database
- Type
- domain
- Value
osx.bella- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.bella
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.bella
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
EXECUTIVE SUMMARY The BellaCiao malware family exemplifies a unique blend of persistence and stealth, as demonstrated through its evolution from .NET to C++ implementations. Initially surfacing in early spring, the malware's distinguishing features include a sophisticated versioning system identifiable through descriptive PDB paths. These paths not only reveal insights into campaign details ...
-
web:assets.adgm.com
Microsoft Exchange The C++ Server in engineering documented in BellaCiao is a custom dropper malware vulnerabilities and India. BellaCPP: payloads (e.g., "D3D12_1core.dll") for creating similar functionality in applications web shell feature that to of BellaCiao, ManageEngine malware , identified including to as establish unauthorized ("adhapl.dll"), to additional Threat malware leveraging ...
-
web:cyberpress.org
BellaCiao is a .NET malware family linked to Charming Kitten, which employs webshell-like persistence and covert tunneling capabilities.
-
web:cybersecsentinel.com
Mitigation and Prevention User Awareness: Conduct regular training to recognize phishing attempts and suspicious activities. Email Filtering: Implement advanced email filtering to detect and block malicious attachments and links. Antivirus Protection: Ensure up-to-date antivirus solutions are in place and regularly scan systems for malware .
-
web:rewterz.com
A C++ version of the well-known malware BellaCiao has been seen being used by the Iranian nation-state APT group Charming Kitten. Researchers who named the new variant BellaCPP found the artifact as part of a recent investigation into a hacked machine in Asia that was also infected with the malware .
-
web:securelist.com
While investigating an incident involving the BellaCiao .NET malware , Kaspersky researchers discovered a C++ version they dubbed "BellaCPP".
-
web:securityaffairs.com
Iran-linked APT group Charming Kitten has been observed using a new variant of the BellaCiao malware dubbed BellaCPP, Kaspersky warns.
-
web:undercodenews.com
2024-12-23 This article delves into the intricacies of the BellaCiao malware family , a persistent threat linked to the notorious Charming Kitten threat actor group. Through an analysis of a recent intrusion investigation, researchers uncovered a new C++ variant, BellaCPP, operating alongside a pre-existing BellaCiao sample.
-
web:www.cyberstash.com
BellaCiao is a dropper malware that delivers other malware payloads onto the victim's computer system. The executable is written to specific locations on the system and runs as a service, using names resembling legitimate Microsoft Exchange services.
-
web:www.threatintelreport.com
The latest findings reveal enhanced capabilities of the malware , including new command-and-control (C2) mechanisms and refined operational tactics. These improvements underscore APT35's commitment to advancing its cyber warfare techniques.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.