s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.sindoor

📛 Threat Title

Malware family: Sindoor

Category: Sindoor First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.sindoor`. Printable name: Sindoor.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.sindoor VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sindoor

IOC database

Type
domain
Value
elf.sindoor
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.sindoor

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sindoor

References (1)

Remediations (10)

  • web:arxiv.org

    The rest of the paper is organized as follows: In Section 2, we provide details about the malware used in the cyber campaign during Operation Sindoor . In Section 3, we discuss about the logging the necessary events to establish telemetry. In Section 4, we provide details about analysis of the telemetry logs and develop a rule to detect the malware .

  • web:blogs.npav.net

    A new malware campaign called " Sindoor Dropper" is targeting Linux systems using spear-phishing tactics tied to the India-Pakistan conflict theme. It spreads via malicious .desktop files disguised as PDF documents, which open a decoy PDF while silently launching a complex, multi-stage infection.

  • web:cyberpress.org

    Operation Sindoor's campaign extended well beyond espionage, layering hacktivist-driven operations atop targeted malware attacks. From May 7-10, Seqrite Labs telemetry recorded over 650 cases of DDoS attacks and website defacement, with at least 35 hacktivist groups seven newly emerged actively contributing to the disruption.

  • web:cybersecsentinel.com

    Malware Used: Sindoor Dropper (Go based multi stage dropper), MeshAgent remote administration agent as the final payload. Threat Score: 🔴 High (7.9/10) - Full remote control on Linux workstations through multi stage obfuscation, anti analysis, and legitimate admin tool abuse; credible targeting of government and defence networks.

  • web:cybersecuritynews.com

    A new malware campaign, dubbed " Sindoor Dropper," is targeting Linux systems using sophisticated spear-phishing techniques and a multi-stage infection chain.

  • web:link.springer.com

    In particular, we study the malware used by Pakistan APT groups to deploy Remote Access Trojans in Indian systems. We provide details of the tactics and techniques used in the RAT deployment and develop a telemetry framework to collect necessary event logs using Osquery with a custom extension.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Sindoor malware family including references, samples and yara signatures.

  • web:socradar.io

    Researchers discovered that the attackers deployed a previously undocumented backdoor known as Dindoor, along with additional malware tools, to maintain access within victim networks. The campaign appears to have started in early 2026 and involved organizations such as a U.S. airport, a bank, a non-profit organization, and a software supplier connected to the defense and aerospace industry.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.nextron-systems.com

    The final payload delivered by the Sindoor dropper is a MeshAgent binary, a legitimate remote administration tool that has been repurposed for malicious use. MeshAgent provides the attacker with full remote access to the compromised system, enabling a wide range of post-exploitation activities such as activity monitoring, lateral movement, data ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.