s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.fontonlake

📛 Threat Title

Malware family: FontOnLake

Category: FontOnLake First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.fontonlake`. Printable name: FontOnLake.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.fontonlake VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fontonlake

IOC database

Type
domain
Value
elf.fontonlake
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.fontonlake

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fontonlake

References (1)

Remediations (10)

  • web:aavar.org

    The sneaky nature of FontOnLake's tools in combination with advanced design and low prevalence suggest that they are used in targeted attacks. The first known file of this malware family appeared on VirusTotal last May and other samples were uploaded throughout the year.

  • web:cybersecuritynews.com

    BPFDoor and Symbiote rootkits exploit eBPF to evade detection, with new 2025 samples showing active, stealthy Linux attacks.

  • web:hackread.com

    According to ESET's researchers, components of FontOnLake malware are divided into three groups: Trojamized app, Rootkit, and Backdoor. Researchers at Slovak cybersecurity company ESET have identified a new malware family utilizing custom and well-designed modules. In ESET's white paper , researchers revealed that the malware dubbed FontOnLake Rootkit malware targets Linux systems and its ...

  • web:linux.slashdot.org

    Security Week reports: A previously unknown, modular malware family that targets Linux systems has been used in targeted attacks to collect credentials and gain access to victim systems, ESET reported on Thursday. Dubbed FontOnLake , the malware family employs a rootkit to conceal its presence an...

  • web:web-assets.esetstatic.com

    FontOnLake is a malware family utilizing well-designed custom modules that are constantly under development It targets systems running Linux and provides remote access to those systems for its operators, collects credentials, and serves as a proxy server Its presence is always accompanied by a rootkit, which conceals its existence

  • web:www.darkreading.com

    A previously unknown malware family dubbed FontOnLake is targeting systems running Linux, ESET researchers found. FontOnLake uses "custom and well-designed modules," malware analyst Vladislav ...

  • web:www.eset.com

    To collect data or conduct other malicious activity, this malware family uses modified legitimate binaries that are adjusted to load further components. In fact, to conceal its existence, FontOnLake's presence is always accompanied by a rootkit. These binaries are commonly used on Linux systems and can additionally serve as a persistence ...

  • web:www.fortiguard.com

    FortiGuard Labs is aware of a new, Linux malware family named " FontOnLake ." FontOnLake is a very sophisticated malware family that contains a Linux rootkit which runs at the kernel level to prolong its shelf life and to ultimately evade detection.

  • web:www.scribd.com

    The document analyzes FontOnLake , a malware family that targets Linux systems. It consists of trojanized applications, backdoors, and rootkits that provide remote access and credential theft capabilities to operators while remaining concealed. The malware appears to be used in targeted attacks, possibly in Southeast Asia, as its command and control servers and uploading locations indicate. It ...

  • web:www.securityweek.com

    A previously unknown, modular malware family that targets Linux systems has been used in targeted attacks to collect credentials and gain access to victim systems, ESET reported on Thursday. Dubbed FontOnLake , the malware family employs a rootkit to conceal its presence and uses different command and control servers for each sample, which shows how careful its operators are to maintain a low ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.