s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.ghostpenguin

📛 Threat Title

Malware family: GhostPenguin

Category: GhostPenguin First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.ghostpenguin`. Printable name: GhostPenguin.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.ghostpenguin VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ghostpenguin

IOC database

Type
domain
Value
elf.ghostpenguin
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.ghostpenguin

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ghostpenguin

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    Malware samples associated with tag GHOSTPENGUIN MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with GHOSTPENGUIN . Database ...

  • web:cyberpress.org

    Cybersecurity researchers at Trend™ Research have uncovered a previously undetected Linux backdoor dubbed GhostPenguin , a sophisticated, multi-threaded malware written in C++. The threat was identified using Trend's AI-driven automated threat hunting pipeline, which collected and analyzed zero-detection samples from VirusTotal.

  • web:cybersecuritynews.com

    A previously undocumented Linux backdoor named GhostPenguin has been discovered evading detection for over four months. This multi-threaded C++ malware establishes remote shell access and file-system operations via encrypted UDP, making it exceptionally difficult to detect with traditional security tools.

  • web:gbhackers.com

    A sophisticated Linux backdoor named GhostPenguin has been discovered by Trend Micro Research, evading detection for over four months after its initial submission to VirusTotal in July 2025. The threat represents a new breed of stealthy malware designed to maintain a low profile while delivering comprehensive remote access and file system manipulation capabilities to threat actors. The malware ...

  • web:meterpreter.org

    A previously obscure Linux backdoor known as GhostPenguin has emerged from the shadows thanks to automated threat hunting, in which Trend Research leveraged AI to analyze thousands of undetected samples from VirusTotal. Analysts uncovered a previously undocumented piece of malware that had evaded all antivirus detection for more than four months, and conducted an in-depth examination of its ...

  • web:redpiranha.net

    In this report, we discuss two new cyber threats, GhostPenguin and EtherRAT. This week's ransomware focus is on Akira Ransomware.

  • web:securitricks.com

    An undocumented Linux backdoor called GhostPenguin was discovered using AI-driven threat hunting. This multi-threaded C++ malware provides remote shell access and file system operations over an encrypted UDP channel. It uses a structured handshake mechanism and synchronizes threads for registration, heartbeat signaling, and command delivery.

  • web:undercodenews.com

    Trend Research identified GhostPenguin using its AI-driven threat hunting pipeline, which scans and analyzes zero-detection malware samples submitted to VirusTotal. The malware sample, disguised as systemd, was first uploaded on July 7, 2025, and remained invisible to all traditional antivirus scanners for over four months.

  • web:www.cybersecurity-now.co.uk

    Trend Vision One™ detects and blocks the specific indicators of compromise (IoCs) mentioned in this blog entry, and offers customers access to hunting queries, threat insights, and intelligence reports related to the GhostPenguin backdoor. Hunting high-impact, advanced malware is a difficult task.

  • web:www.trendmicro.com

    In this blog entry, Trend™ Research provides a comprehensive breakdown of GhostPenguin , a previously undocumented Linux backdoor with low detection rates that was discovered through AI-powered threat hunting and in-depth malware analysis.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.