TF-MAL-elf.fontonlake
📛 Threat Title
Malware family: FontOnLake
Description
ThreatFox malware family `elf.fontonlake`. Printable name: FontOnLake.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.fontonlake
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fontonlake
IOC database
- Type
- domain
- Value
elf.fontonlake- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.fontonlake
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fontonlake
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:aavar.org
The sneaky nature of FontOnLake's tools in combination with advanced design and low prevalence suggest that they are used in targeted attacks. The first known file of this malware family appeared on VirusTotal last May and other samples were uploaded throughout the year.
-
web:cybersecuritynews.com
BPFDoor and Symbiote rootkits exploit eBPF to evade detection, with new 2025 samples showing active, stealthy Linux attacks.
-
web:hackread.com
According to ESET's researchers, components of FontOnLake malware are divided into three groups: Trojamized app, Rootkit, and Backdoor. Researchers at Slovak cybersecurity company ESET have identified a new malware family utilizing custom and well-designed modules. In ESET's white paper , researchers revealed that the malware dubbed FontOnLake Rootkit malware targets Linux systems and its ...
-
web:linux.slashdot.org
Security Week reports: A previously unknown, modular malware family that targets Linux systems has been used in targeted attacks to collect credentials and gain access to victim systems, ESET reported on Thursday. Dubbed FontOnLake , the malware family employs a rootkit to conceal its presence an...
-
web:web-assets.esetstatic.com
FontOnLake is a malware family utilizing well-designed custom modules that are constantly under development It targets systems running Linux and provides remote access to those systems for its operators, collects credentials, and serves as a proxy server Its presence is always accompanied by a rootkit, which conceals its existence
-
web:www.darkreading.com
A previously unknown malware family dubbed FontOnLake is targeting systems running Linux, ESET researchers found. FontOnLake uses "custom and well-designed modules," malware analyst Vladislav ...
-
web:www.eset.com
To collect data or conduct other malicious activity, this malware family uses modified legitimate binaries that are adjusted to load further components. In fact, to conceal its existence, FontOnLake's presence is always accompanied by a rootkit. These binaries are commonly used on Linux systems and can additionally serve as a persistence ...
-
web:www.fortiguard.com
FortiGuard Labs is aware of a new, Linux malware family named " FontOnLake ." FontOnLake is a very sophisticated malware family that contains a Linux rootkit which runs at the kernel level to prolong its shelf life and to ultimately evade detection.
-
web:www.scribd.com
The document analyzes FontOnLake , a malware family that targets Linux systems. It consists of trojanized applications, backdoors, and rootkits that provide remote access and credential theft capabilities to operators while remaining concealed. The malware appears to be used in targeted attacks, possibly in Southeast Asia, as its command and control servers and uploading locations indicate. It ...
-
web:www.securityweek.com
A previously unknown, modular malware family that targets Linux systems has been used in targeted attacks to collect credentials and gain access to victim systems, ESET reported on Thursday. Dubbed FontOnLake , the malware family employs a rootkit to conceal its presence and uses different command and control servers for each sample, which shows how careful its operators are to maintain a low ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.