TF-MAL-elf.grimbolt
📛 Threat Title
Malware family: GRIMBOLT
Description
ThreatFox malware family `elf.grimbolt`. Printable name: GRIMBOLT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.grimbolt
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.grimbolt
IOC database
- Type
- domain
- Value
elf.grimbolt- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.grimbolt
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.grimbolt
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cloud.google.com
GRIMBOLT represents a shift in tradecraft; this newly identified malware , written in C# and compiled using native ahead-of-time (AOT) compilation, is designed to complicate static analysis and enhance performance on resource-constrained appliances.
-
web:cyberpress.org
Dell patched this urgently; upgrade to version 6.0.3.1 HF1 or run their remediation script now. Hunt Tomcat logs for /manager hits, isolate affected appliances, and monitor VMware for odd NICs. With UNC6201's evolving tricks, quick action blocks espionage chains. Stay vigilant as state actors refine these plays.
-
web:cybersecuritynews.com
A critical zero-day exploitation campaign targeting Dell RecoverPoint for Virtual Machines. The attackers have utilized this flaw to move laterally across networks, maintain persistent access, and deploy a suite of sophisticated malware , including SLAYSTYLE, BRICKSTORM, and a novel backdoor identified as GRIMBOLT .
-
web:cyberwebspider.com
The evolution of this campaign includes transitioning from BRICKSTORM to GRIMBOLT , a more advanced malware . Unlike typical .NET malware , GRIMBOLT is written in C# and compiled using Native Ahead-of-Time compilation, enhancing its stealth and efficiency in constrained environments. Mitigation and Future Implications
-
web:gixtools.net
GRIMBOLT During analysis of compromised Dell RecoverPoint for Virtual Machines, Mandiant discovered the presence of BRICKSTORM binaries and the subsequent replacement of these binaries with GRIMBOLT in September 2025. GRIMBOLT is a C#-written foothold backdoor compiled using native ahead-of-time (AOT) compilation and packed with UPX.
-
web:petri.com
Chinese APT exploited a Dell RecoverPoint zero-day for two years, deploying malware and gaining persistent access to VMware environments.
-
web:socprime.com
Tracked with a CVSS score of 10.0, CVE-2026-22769 has reportedly been exploited by the China-linked cluster UNC6201 since at least mid-2024, enabling attackers to establish access and deploy multiple malware families, including BRICKSTORM and GRIMBOLT .
-
web:thehackernews.com
Dell RecoverPoint zero-day CVE-2026-22769 exploited since 2024 to gain root access and deploy GRIMBOLT , BRICKSTORM backdoors in targeted attacks.
-
web:www.threatintelreport.com
Apply Dell remediation guidance: Upgrade and/or mitigation steps depending on supported versions 1. Dell advisory for CVE-2026-22769 (DSA-2026-079) 1 If compromise is suspected: Treat the appliance as untrusted, preserve evidence, and consider rebuilding or restoring from a known-good image.
-
web:www.toddpigram.com
GRIMBOLT represents a shift in tradecraft; this newly identified malware , written in C# and compiled using native ahead-of-time (AOT) compilation, is designed to complicate static analysis and enhance performance on resource-constrained appliances.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.