s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.pithook

📛 Threat Title

Malware family: PITHOOK

Category: PITHOOK First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.pithook`. Printable name: PITHOOK.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.pithook VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pithook

IOC database

Type
domain
Value
elf.pithook
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.pithook

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pithook

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    UNC5325 is utilizing CVE-2024-21893 has deployed a series of new malware strains like LITTLELAMB.WOOLTEA and PITSTOP, enabling persistent access to compromised systems. There is moderate confidence that UNC5325 is associated with UNC3886 due to overlaps in the source code of LITTLELAMB.WOOLTEA and PITHOOK malware used by both groups.

  • web:attack.mitre.org

    PITSTOP is a backdoor that was deployed on compromised Ivanti Connect Secure VPNs during Cutting Edge to enable command execution and file read/write. [1]

  • web:blog.kowatek.com

    UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK , as well as attempted to maintain persistent access to compromised appliances, Mandiant said.

  • web:cloud.google.com

    UNC5325 leveraged code from open-source projects, installed custom malware , and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK .

  • web:gixtools.net

    By GIXnews / February 29, 2024 At least two different suspected China-linked cyber espionage clusters, tracked as UNC5325 and UNC3886, have been attributed to the exploitation of security flaws in Ivanti Connect Secure VPN appliances. UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK , as well as maintain persistent

  • web:malpedia.caad.fkie.fraunhofer.de

    UNC5325 leveraged code from open-source projects, installed custom malware , and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK .

  • web:oodaloop.com

    Despite the flaws being patched on January 31, with one addressed earlier, attackers continued to exploit them, specifically targeting a server-side request forgery (SSRF) vulnerability (CVE-2024-21893) to deploy new malware families such as LittleLamb.WoolTea, PitStop, Pitdog, PitJet, and PitHook .

  • web:sect.iij.ad.jp

    In June 2025, we discovered the dropper of new TINYSHELL based Linux malware . Because this malware had code overlapping with PITHOOK , reported to be used by UNC5325, we are confident that this malware is related to attack campaign of UNC5325. UNC5325 is suspected to be China-nexus espionage actor, whose reported to be exploiting vulnerability of Ivanti Connect Secure (CVE-2024-21893) in the ...

  • web:www.bitdefender.com

    According to the advisory (FLASH-20260219-001), cybercriminals are increasingly deploying sophisticated malware — particularly variants of the Ploutus family — to force Automated Teller Machines (ATMs) to dispense cash without any legitimate transaction or bank authorization.

  • web:www.linkedin.com

    UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK , as well as maintain persistent access to compromised ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.