s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.kobalos

📛 Threat Title

Malware family: Kobalos

Category: Kobalos First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.kobalos`. Printable name: Kobalos.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.kobalos VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kobalos

IOC database

Type
domain
Value
elf.kobalos
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.kobalos

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kobalos

References (1)

Remediations (10)

  • web:attack.mitre.org

    Kobalos is a multi-platform backdoor that can be used against Linux, FreeBSD, and Solaris. Kobalos has been deployed against high profile targets, including high-performance computers, academic servers, an endpoint security vendor, and a large internet service provider; it has been found in Europe, North America, and Asia.

  • web:cybernews.com

    The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.

  • web:github.com

    Indicators of Compromises (IOC) of our various investigations - eset/ malware -ioc

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Kobalos malware family including references, samples and yara signatures.

  • web:support.trellix.com

    Summary Description of Campaign Kobalos malware targeted high-performance computers, academia, an endpoint security vendor, government agencies, personal servers, a marketing agency, hosting firms, and a large ISP. The entities stretch across Europe, North America, and Asia. The multiplatform backdoor works on Linux, FreeBSD, and Solaris. An SSH credential stealer was also discovered on ...

  • web:web-assets.esetstatic.com

    The network capabilities of Kobalos make this malware quite distinctive. It supports acting both as a passive implant and as a bot actively connecting to its C&C server. Interestingly, these C&C servers are themselves compromised with Kobalos ; the code for running such servers is present in all Kobalos samples.

  • web:www.bankinfosecurity.com

    The malware targets a wide range of operating systems, including Linux, BSD and Solaris, and Kobalos might also have the ability to compromise supercomputers that run AIX and Windows, the report ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.eset.com

    ESET researchers discovered Kobalos , a malware that has been attacking supercomputers - high performance computer (HPC) clusters. ESET has worked with the CERN Computer Security Team and other organizations involved in mitigating attacks on these scientific research networks.

  • web:www.securityweek.com

    ESET details Kobalos , a sophisticated multiplatform malware that has been observed targeting several high-performance computers and other types of organizations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.