s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.horseshell

📛 Threat Title

Malware family: Horse Shell

Category: Horse Shell First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.horseshell`. Printable name: Horse Shell.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.horseshell VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.horseshell

IOC database

Type
domain
Value
elf.horseshell
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.horseshell

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.horseshell

References (1)

Remediations (10)

  • web:blog.sucuri.net

    What is a web shell ? Learn about the most common types, along with examples. We explain how shells work, what they do, and how to protect your site and clean up this malware from a hacked server.

  • web:cybersecuritynews.com

    Recently, the cybersecurity experts at Checkpoint identified that the Chinese state-sponsored group "Camaro Dragon" employs a custom " Horse Shell " malware embedded in TP-Link routers' firmware to target European foreign affairs organizations, leveraging residential networks for their attacks.

  • web:malpedia.caad.fkie.fraunhofer.de

    Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor "Camaro Dragon", a custom MIPS32 ELF implant. HorseShell , the main implant inserted into the modified firmware by the attackers, provides the attacker with 3 main functionalities: * Remote shell : Execution of arbitrary shell commands on the infected router * File transfer ...

  • web:www.bleepingcomputer.com

    A Chinese state-sponsored hacking group named "Camaro Dragon" infects residential TP-Link routers with a custom " Horse Shell " malware used to attack European foreign affairs organizations.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.laptopmag.com

    The " Horse Shell " malware has already been found to play a part in the targeting of European foreign affairs entities — piggybacking through several of these infected nodes as it went.

  • web:www.techradar.com

    Targeting poorly secured devices While the researchers found Horse Shell on TP-Link routers, they claim the malware is firmware-agnostic, and doesn't target specific brands.

  • web:www.thestack.technology

    A unique new malicious router firmware implant dubbed " Horse Shell " is being deployed by a Chinese threat group for unknown purposes.

  • web:www.virusbulletin.com

    The firmware image contained several malicious components, including a custom MIPS32 ELF implant dubbed 'Horse Shell' . In addition to the implant, a passive backdoor providing the attackers with a shell to infected devices was found.

  • web:www.voicendata.com

    Malicious firmware implant " Horse Shell " targeting popular TP-Link routers Check Point Research (CPR) has been monitoring a series of targeted cyberattacks on European foreign affairs entities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.