TF-MAL-elf.drive_switch
📛 Threat Title
Malware family: DriveSwitch
Description
ThreatFox malware family `elf.drive_switch`. Printable name: DriveSwitch.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arxiv.org
Abstract. Determining the family to which a malicious file belongs is an essential component of cyberattack investigation, attribution, and remediation . Performing this task manually is time consuming and requires expert knowledge. Automated tools using that label malware using antivirus detections lack accuracy and/or scalability, making them insufficient for real-world applications. Three ...
-
web:industrialcyber.co
Researchers from Cisco Talos disclosed a sophisticated threat actor, tracked as UAT-7290, which has been active since at least 2022. The group is assessed as responsible for gaining initial access and conducting espionage-focused intrusions against critical infrastructure entities in South Asia. These hackers employ a dedicated malware arsenal that includes a family of implants referred to as ...
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:securityaffairs.com
The role of DriveSwitch is to launch SilentRaid, the main backdoor. SilentRaid is modular malware that contacts a command-and-control server and executes tasks through built-in plugins. These plugins enable remote shells, file access, port forwarding, command execution, and data collection, including system files and certificate details.
-
web:windowsforum.com
The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.kodemsecurity.com
CVE-2026-31431, the Copy Fail Linux kernel LPE, lets authenticated users gain root. See affected kernels, exploit details, IOCs and patches.
-
web:www.mdpabel.com
Got a SWITCH deactivation warning for drive-by malware on your .ch site? Real case study: how I unsuspended the domain in 30 min and cleaned 1,589 infected files
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.