TF-MAL-elf.kobalos
📛 Threat Title
Malware family: Kobalos
Description
ThreatFox malware family `elf.kobalos`. Printable name: Kobalos.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.kobalos
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kobalos
IOC database
- Type
- domain
- Value
elf.kobalos- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.kobalos
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kobalos
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Kobalos is a multi-platform backdoor that can be used against Linux, FreeBSD, and Solaris. Kobalos has been deployed against high profile targets, including high-performance computers, academic servers, an endpoint security vendor, and a large internet service provider; it has been found in Europe, North America, and Asia.
-
web:cybernews.com
The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.
-
web:github.com
Indicators of Compromises (IOC) of our various investigations - eset/ malware -ioc
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Kobalos malware family including references, samples and yara signatures.
-
web:support.trellix.com
Summary Description of Campaign Kobalos malware targeted high-performance computers, academia, an endpoint security vendor, government agencies, personal servers, a marketing agency, hosting firms, and a large ISP. The entities stretch across Europe, North America, and Asia. The multiplatform backdoor works on Linux, FreeBSD, and Solaris. An SSH credential stealer was also discovered on ...
-
web:web-assets.esetstatic.com
The network capabilities of Kobalos make this malware quite distinctive. It supports acting both as a passive implant and as a bot actively connecting to its C&C server. Interestingly, these C&C servers are themselves compromised with Kobalos ; the code for running such servers is present in all Kobalos samples.
-
web:www.bankinfosecurity.com
The malware targets a wide range of operating systems, including Linux, BSD and Solaris, and Kobalos might also have the ability to compromise supercomputers that run AIX and Windows, the report ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.eset.com
ESET researchers discovered Kobalos , a malware that has been attacking supercomputers - high performance computer (HPC) clusters. ESET has worked with the CERN Computer Security Team and other organizations involved in mitigating attacks on these scientific research networks.
-
web:www.securityweek.com
ESET details Kobalos , a sophisticated multiplatform malware that has been observed targeting several high-performance computers and other types of organizations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.