Skip to content

[Intel]: https://github.com/Neo23x0/signature-base/blob/master/yara/mal_lnx_implant_may22.yar #419

Open
@timb-machine

Description

Area

Other rules

Parent threat

No response

Finding

https://github.com/Neo23x0/signature-base/blob/master/yara/mal_lnx_implant_may22.yar

Industry reference

attack:T1205.002:Socket Filters

Malware reference

BPFDoor
Tricephalic Hellkeeper
Unix.Backdoor.RedMenshen
JustForFun
#418

Actor reference

DecisiveArchitect

Component

Linux

Scenario

No response

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions