TF-MAL-elf.evilgnome
📛 Threat Title
Malware family: EvilGnome
Description
ThreatFox malware family `elf.evilgnome`. Printable name: EvilGnome.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.evilgnome
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.evilgnome
IOC database
- Type
- domain
- Value
elf.evilgnome- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.evilgnome
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.evilgnome
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:archive.org
We can, however, observe similarities at a high-level. The techniques and modules employed by EvilGnome—that is the use of SFX, persistence with task scheduler and the deployment of information stealing tools—remind us of Gamaredon Group's Windows tools. We present a thorough analysis of EvilGnome in the following section.
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:intezer.com
EvilGnome , a rare type of malware with zero detections in VirusTotal, is spying on Linux desktop users by allowing the recording of audio conversations. The malware has infrastructure connections to Russian APT Gamaredon Group.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Infosec Institute, EvilGnome presents itself to unwitting Linux users as a legitimate GNOME extension. Legitimate extensions help to extend Linux functionality, but instead of a healthy boost in system functionality, EvilGnome begins spying on users with an array of functionalities uncommon for most Linux malware types.
-
web:secalerts.co
Linux systems are being targeted by a new backdoor spyware, dubbed EvilGnome because it disguises itself as a Gnome extension, reports security company Intezer. Intezer believe "this is a test version that was uploaded to VirusTotal (which analyse suspicious files and URLs to detect types of malware ), perhaps by mistake.
-
web:theweborion.com
A new Linux malware masquerading as a Gnome shell extension and designed to spy on unsuspecting Linux desktop users was discovered by Intezer Labs' researchers in early July. " Evil Gnome's functionalities include desktop screenshots, file stealing, allowing capturing audio recording from the user's microphone and the ability to download and execute further modules," Intezer ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.defenxor.com
Discovered in July 2019, this new Linux malware masquerading as a Gnome shell extension and designed to spy on unsuspecting Linux desktop users. The backdoor implant dubbed EvilGnome is currently not detected by any of the anti- malware engines and has been designed to take desktop screenshots, steal files, capture audio recordings from a user ...
-
web:www.infosecinstitute.com
Introduction The name EvilGnome may conjure images of a malicious creature of folklore. Instead, this name actually refers to an emerging type of malware recently detected by malware researchers. This article will detail the EvilGnome malware family .
-
web:www.thelinuxmall.com
The Gnome extension on Linux is carrying a malware in disguise. The ones who made the find were the people working at Intezer. They have even linked the malicious code as spyware created by Russian coders named Gamaredon. Most of the modules used by the malicious code in Evil-Gnomeis tied to Windows utilities such as the use of SFX, task scheduler and data trackers. Since the code seems to ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.