TF-MAL-elf.pithook
📛 Threat Title
Malware family: PITHOOK
Description
ThreatFox malware family `elf.pithook`. Printable name: PITHOOK.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.pithook
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pithook
IOC database
- Type
- domain
- Value
elf.pithook- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.pithook
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.pithook
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
UNC5325 is utilizing CVE-2024-21893 has deployed a series of new malware strains like LITTLELAMB.WOOLTEA and PITSTOP, enabling persistent access to compromised systems. There is moderate confidence that UNC5325 is associated with UNC3886 due to overlaps in the source code of LITTLELAMB.WOOLTEA and PITHOOK malware used by both groups.
-
web:attack.mitre.org
PITSTOP is a backdoor that was deployed on compromised Ivanti Connect Secure VPNs during Cutting Edge to enable command execution and file read/write. [1]
-
web:blog.kowatek.com
UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK , as well as attempted to maintain persistent access to compromised appliances, Mandiant said.
-
web:cloud.google.com
UNC5325 leveraged code from open-source projects, installed custom malware , and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK .
-
web:gixtools.net
By GIXnews / February 29, 2024 At least two different suspected China-linked cyber espionage clusters, tracked as UNC5325 and UNC3886, have been attributed to the exploitation of security flaws in Ivanti Connect Secure VPN appliances. UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK , as well as maintain persistent
-
web:malpedia.caad.fkie.fraunhofer.de
UNC5325 leveraged code from open-source projects, installed custom malware , and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK .
-
web:oodaloop.com
Despite the flaws being patched on January 31, with one addressed earlier, attackers continued to exploit them, specifically targeting a server-side request forgery (SSRF) vulnerability (CVE-2024-21893) to deploy new malware families such as LittleLamb.WoolTea, PitStop, Pitdog, PitJet, and PitHook .
-
web:sect.iij.ad.jp
In June 2025, we discovered the dropper of new TINYSHELL based Linux malware . Because this malware had code overlapping with PITHOOK , reported to be used by UNC5325, we are confident that this malware is related to attack campaign of UNC5325. UNC5325 is suspected to be China-nexus espionage actor, whose reported to be exploiting vulnerability of Ivanti Connect Secure (CVE-2024-21893) in the ...
-
web:www.bitdefender.com
According to the advisory (FLASH-20260219-001), cybercriminals are increasingly deploying sophisticated malware — particularly variants of the Ploutus family — to force Automated Teller Machines (ATMs) to dispense cash without any legitimate transaction or bank authorization.
-
web:www.linkedin.com
UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK , as well as maintain persistent access to compromised ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.