s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.evilgnome

📛 Threat Title

Malware family: EvilGnome

Category: EvilGnome First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.evilgnome`. Printable name: EvilGnome.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.evilgnome VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.evilgnome

IOC database

Type
domain
Value
elf.evilgnome
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.evilgnome

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.evilgnome

References (1)

Remediations (10)

  • web:archive.org

    We can, however, observe similarities at a high-level. The techniques and modules employed by EvilGnome—that is the use of SFX, persistence with task scheduler and the deployment of information stealing tools—remind us of Gamaredon Group's Windows tools. We present a thorough analysis of EvilGnome in the following section.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:intezer.com

    EvilGnome , a rare type of malware with zero detections in VirusTotal, is spying on Linux desktop users by allowing the recording of audio conversations. The malware has infrastructure connections to Russian APT Gamaredon Group.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Infosec Institute, EvilGnome presents itself to unwitting Linux users as a legitimate GNOME extension. Legitimate extensions help to extend Linux functionality, but instead of a healthy boost in system functionality, EvilGnome begins spying on users with an array of functionalities uncommon for most Linux malware types.

  • web:secalerts.co

    Linux systems are being targeted by a new backdoor spyware, dubbed EvilGnome because it disguises itself as a Gnome extension, reports security company Intezer. Intezer believe "this is a test version that was uploaded to VirusTotal (which analyse suspicious files and URLs to detect types of malware ), perhaps by mistake.

  • web:theweborion.com

    A new Linux malware masquerading as a Gnome shell extension and designed to spy on unsuspecting Linux desktop users was discovered by Intezer Labs' researchers in early July. " Evil Gnome's functionalities include desktop screenshots, file stealing, allowing capturing audio recording from the user's microphone and the ability to download and execute further modules," Intezer ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.defenxor.com

    Discovered in July 2019, this new Linux malware masquerading as a Gnome shell extension and designed to spy on unsuspecting Linux desktop users. The backdoor implant dubbed EvilGnome is currently not detected by any of the anti- malware engines and has been designed to take desktop screenshots, steal files, capture audio recordings from a user ...

  • web:www.infosecinstitute.com

    Introduction The name EvilGnome may conjure images of a malicious creature of folklore. Instead, this name actually refers to an emerging type of malware recently detected by malware researchers. This article will detail the EvilGnome malware family .

  • web:www.thelinuxmall.com

    The Gnome extension on Linux is carrying a malware in disguise. The ones who made the find were the people working at Intezer. They have even linked the malicious code as spyware created by Russian coders named Gamaredon. Most of the modules used by the malicious code in Evil-Gnomeis tied to Windows utilities such as the use of SFX, task scheduler and data trackers. Since the code seems to ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.