s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.melofee

📛 Threat Title

Malware family: Melofee

Category: Melofee First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.melofee`. Printable name: Melofee. Aliases: Mélofée.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.melofee VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.melofee

IOC database

Type
domain
Value
elf.melofee
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.melofee

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.melofee

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    A new type of malware targeted at Linux systems has been connected to an unidentified Chinese state-sponsored hacking group. Researchers discovered three samples of the previously known dangerous software known as Mélofée which was first discovered in early 2022.

  • web:archive.org

    / melofee / Mélofée : a new alien malware in the Panda's toolset targeting Linux hosts We recently discovered an novel undetected implant family targeting Linux servers, which we dubbed Mélofée We linked with high confidence this malware to chinese state sponsored APT groups, in particular the notorious Winnti

  • web:archive.orkl.eu

    Hellobot HelloBot is a malware family also targeting Linux hosts and is known to be used by APT groups such as Earth Berberoka . While pivoting on the Mélofée infrastructure, we found a common IP with an HelloBot sample, which provided another point to dig in.

  • web:blog.exatrack.com

    We recently discovered an novel undetected implant family targeting Linux servers, which we dubbed Mélofée . We linked with high confidence this malware to chinese state sponsored APT groups, in particular the notorious Winnti group. In this blogpost we will first analyze the capabilities offered by this malware family , which include a kernel mode rootkit, and then deep dive in an ...

  • web:blog.xlab.qianxin.com

    Summary Melofee offers straightforward functionality with highly effective stealth capabilities. Samples of this malware family are rare, suggesting that attackers may limit its use to high-value targets. Network administrators can check for infection by looking for artifacts like the /tmp/lock_tmp1 file and the kworkerx module.

  • web:cybersecuritynews.com

    ExaTrack found a new undetected implant family called Mélofée that targets Linux systems. Three samples of the previously known malicious software, dating from the beginning of 2022, were found by analysts. Chinese state-sponsored APT groups, including the notorious Winnti group, are related to the malware . Capabilities of Mélofée Researchers analyzed this malware family's capabilities ...

  • web:linuxsecurity.com

    The discovery of a novel malware piece targeting Linux servers has been attributed to an unknown Chinese state-sponsored hacking group. A state-sponsored APT group called Earth Berberoka (GamblingPuppet) has also been linked to this malware . While this group has been active since 2020 and primarily targets Chinese gambling websites.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Melofee malware family including references, samples and yara signatures.

  • web:sandflysecurity.com

    A new report from Qianxin's X Lab was released detailing new stealth malware targeting Red Hat 7.9 and similar systems: New Zero-Detection Variant of Melofee Backdoor from Winnti Strikes RHEL 7.9 This malware currently shows zero detection coverage at Virus Total as of today, but Sandfly was able to easily see it operating.

  • web:securityaffairs.com

    Researchers also pointed out that the HelloBot Linux malware family , linked to Winnti APT group, shared Mélofée infrastructure. The experts also discovered another malware tracked as AlienReverse, which appears to be similar to Mélofée and includes public tools like tools EarthWorm and socks_proxy.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.