TF-MAL-elf.ghostpenguin
📛 Threat Title
Malware family: GhostPenguin
Description
ThreatFox malware family `elf.ghostpenguin`. Printable name: GhostPenguin.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.ghostpenguin
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ghostpenguin
IOC database
- Type
- domain
- Value
elf.ghostpenguin- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.ghostpenguin
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ghostpenguin
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
Malware samples associated with tag GHOSTPENGUIN MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with GHOSTPENGUIN . Database ...
-
web:cyberpress.org
Cybersecurity researchers at Trend™ Research have uncovered a previously undetected Linux backdoor dubbed GhostPenguin , a sophisticated, multi-threaded malware written in C++. The threat was identified using Trend's AI-driven automated threat hunting pipeline, which collected and analyzed zero-detection samples from VirusTotal.
-
web:cybersecuritynews.com
A previously undocumented Linux backdoor named GhostPenguin has been discovered evading detection for over four months. This multi-threaded C++ malware establishes remote shell access and file-system operations via encrypted UDP, making it exceptionally difficult to detect with traditional security tools.
-
web:gbhackers.com
A sophisticated Linux backdoor named GhostPenguin has been discovered by Trend Micro Research, evading detection for over four months after its initial submission to VirusTotal in July 2025. The threat represents a new breed of stealthy malware designed to maintain a low profile while delivering comprehensive remote access and file system manipulation capabilities to threat actors. The malware ...
-
web:meterpreter.org
A previously obscure Linux backdoor known as GhostPenguin has emerged from the shadows thanks to automated threat hunting, in which Trend Research leveraged AI to analyze thousands of undetected samples from VirusTotal. Analysts uncovered a previously undocumented piece of malware that had evaded all antivirus detection for more than four months, and conducted an in-depth examination of its ...
-
web:redpiranha.net
In this report, we discuss two new cyber threats, GhostPenguin and EtherRAT. This week's ransomware focus is on Akira Ransomware.
-
web:securitricks.com
An undocumented Linux backdoor called GhostPenguin was discovered using AI-driven threat hunting. This multi-threaded C++ malware provides remote shell access and file system operations over an encrypted UDP channel. It uses a structured handshake mechanism and synchronizes threads for registration, heartbeat signaling, and command delivery.
-
web:undercodenews.com
Trend Research identified GhostPenguin using its AI-driven threat hunting pipeline, which scans and analyzes zero-detection malware samples submitted to VirusTotal. The malware sample, disguised as systemd, was first uploaded on July 7, 2025, and remained invisible to all traditional antivirus scanners for over four months.
-
web:www.cybersecurity-now.co.uk
Trend Vision One™ detects and blocks the specific indicators of compromise (IoCs) mentioned in this blog entry, and offers customers access to hunting queries, threat insights, and intelligence reports related to the GhostPenguin backdoor. Hunting high-impact, advanced malware is a difficult task.
-
web:www.trendmicro.com
In this blog entry, Trend™ Research provides a comprehensive breakdown of GhostPenguin , a previously undocumented Linux backdoor with low detection rates that was discovered through AI-powered threat hunting and in-depth malware analysis.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.