-
Notifications
You must be signed in to change notification settings - Fork 92
Issues: timb-machine/linux-malware
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
[Intel]: https://github.com/MegaManSec/SSH-Snake
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:T1005
missing:tag:T1021.002
missing:tag:T1021.004
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1098.004
missing:tag:T1548.003
missing:tag:T1552.003
missing:tag:T1552.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#791
opened Jan 30, 2024 by
timb-machine
[Intel]: https://github.com/marin-m/vmlinux-to-elf
missing:tag:IRC
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1518
missing:tag:T1548.003
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#726
opened Jul 15, 2023 by
timb-machine
[Intel]: https://github.com/89luca89/pakkero
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:ProcessTreeSpoofing
missing:tag:T1005
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1053.007
missing:tag:T1057
missing:tag:T1059.006
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1548.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.006
missing:tag:T1574.007
missing:tag:T1590
missing:tag:T1609
missing:tag:T1610
new
#718
opened Jul 14, 2023 by
timb-machine
[Intel]: https://reveng007.github.io/blog/2022/03/08/reveng_rkit_detailed.html
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:RedirectionToNull
missing:tag:T1005
missing:tag:T1021.002
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
#705
opened Jun 26, 2023 by
timb-machine
[Intel]: https://blog.sucuri.net/2023/04/balada-injector-synopsis-of-a-massive-ongoing-wordpress-malware-campaign.html
missing:tag:Go
missing:tag:IRC
missing:tag:JavaScript
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1552.003
missing:tag:T1558
missing:tag:T1560
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#637
opened Apr 15, 2023 by
timb-machine
[Intel]: https://github.com/david942j/seccomp-tools
missing:tag:IRC
missing:tag:ProcessTreeSpoofing
missing:tag:RedirectionToNull
missing:tag:T1005
missing:tag:T1027.004
missing:tag:T1048
missing:tag:T1057
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1518
missing:tag:T1548.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#590
opened Nov 22, 2022 by
timb-machine
[Intel]: https://www.bitdefender.com/files/News/CaseStudies/study/376/Bitdefender-Whitepaper-IPStorm.pdf
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:T1021.002
missing:tag:T1021.004
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1518
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:wltm
#493
opened Aug 8, 2022 by
timb-machine
[Intel]: https://grugq.github.io/docs/subversiveld.pdf
missing:tactics
missing:tag:IRC
missing:tag:T1021.002
missing:tag:T1048
missing:tag:T1055.008
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1567
missing:tag:T1573
missing:tag:T1622
new
#473
opened Jul 23, 2022 by
timb-machine
[Intel]: https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/cyber-year-in-retrospect/yir-cyber-threats-report-download.pdf
missing:tactics
missing:tag:IRC
missing:tag:T1021.002
missing:tag:T1021.004
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1053.003
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1518
missing:tag:T1552.003
missing:tag:T1560
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
#417
opened May 6, 2022 by
timb-machine
[Intel]: https://blog.malwaremustdie.org/2019/09/mmd-0064-2019-linuxairdropbot.html
missing:tactics
missing:tag:IRC
missing:tag:T1003.008
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.006
missing:tag:T1590
new
#366
opened Apr 20, 2022 by
timb-machine
[Intel]: http://www.welivesecurity.com/wp-content/uploads/2015/05/Dissecting-LinuxMoose.pdf
missing:tactics
missing:tag:IRC
missing:tag:T1021.002
missing:tag:T1040
missing:tag:T1046
missing:tag:T1048
missing:tag:T1053.003
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1222
missing:tag:T1548.001
missing:tag:T1567
missing:tag:T1590
new
#349
opened Apr 20, 2022 by
timb-machine
[Intel]: https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-cloud-snooper-report.pdf
missing:tactics
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:RedirectionToNull
missing:tag:T1005
missing:tag:T1021.001
missing:tag:T1046
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1083
missing:tag:T1215
missing:tag:T1546.004
missing:tag:T1548.003
missing:tag:T1552.003
missing:tag:T1562.004
missing:tag:T1573
missing:tag:T1574.007
missing:tag:T1590
missing:tag:wltm
new
#333
opened Apr 20, 2022 by
timb-machine
[Intel]: http://www.ouah.org/LKM_HACKING.html
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:ProcessTreeSpoofing
missing:tag:ProcessTreeSpoofingForking
missing:tag:T1003.008
missing:tag:T1005
missing:tag:T1021.002
missing:tag:T1027.004
missing:tag:T1048
missing:tag:T1055.008
missing:tag:T1055.012
missing:tag:T1057
missing:tag:T1070.002
missing:tag:T1070.004
missing:tag:T1070.006
missing:tag:T1071.001
missing:tag:T1071.002
missing:tag:T1078.003
missing:tag:T1083
missing:tag:T1215
missing:tag:T1222
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1548.001
missing:tag:T1567
missing:tag:T1574.006
missing:tag:T1574.007
missing:tag:T1590
missing:tag:T1622
#257
opened Apr 20, 2022 by
timb-machine
[Intel]: https://is.muni.cz/el/fi/jaro2011/PV204/um/LinuxRootkits/sys_call_table_complete.htm
missing:tag:IRC
missing:tag:T1005
missing:tag:T1021.002
missing:tag:T1027.004
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1215
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1548.003
missing:tag:T1567
missing:tag:T1590
#254
opened Apr 20, 2022 by
timb-machine
[Intel]: https://github.com/JonathonReinhart/nosecmem
missing:tactics
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:T1005
missing:tag:T1027.004
missing:tag:T1048
missing:tag:T1057
missing:tag:T1071.001
missing:tag:T1215
missing:tag:T1548.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1620
new
#180
opened Apr 20, 2022 by
timb-machine
[Intel]: https://github.com/mempodippy/vlany
missing:tactics
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:T1005
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1222
missing:tag:T1548.001
missing:tag:T1560
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.006
new
#174
opened Apr 20, 2022 by
timb-machine
[Intel]: https://github.com/zMarch/Orc
missing:tactics
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:T1005
missing:tag:T1021.001
missing:tag:T1021.002
missing:tag:T1021.004
missing:tag:T1048
missing:tag:T1053.007
missing:tag:T1057
missing:tag:T1070.002
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1222
missing:tag:T1491
missing:tag:T1548.001
missing:tag:T1548.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.007
missing:tag:T1590
missing:tag:T1609
missing:tag:T1610
new
#161
opened Apr 19, 2022 by
timb-machine
[Intel]: https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:ProcessTreeSpoofing
missing:tag:T1005
missing:tag:T1021.002
missing:tag:T1048
missing:tag:T1053.003
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1518
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#99
opened Apr 19, 2022 by
timb-machine
[Intel]: https://blog.malwaremustdie.org/2020/02/mmd-0065-2021-linuxmirai-fbot-re.html
missing:tactics
missing:tag:IRC
missing:tag:T1003.008
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1059.006
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1205
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.006
missing:tag:T1590
new
#59
opened Apr 19, 2022 by
timb-machine
[Intel]: https://blog.malwaremustdie.org/2020/01/mmd-0065-2020-linuxmirai-fbot.html
missing:tactics
missing:tag:IRC
missing:tag:T1003.008
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1071.002
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.006
missing:tag:T1590
new
#58
opened Apr 19, 2022 by
timb-machine
[Intel]: https://blog.malwaremustdie.org/2016/08/mmd-0056-2016-linuxmirai-just.html
missing:tactics
missing:tag:IRC
missing:tag:ProcessTreeSpoofing
missing:tag:ProcessTreeSpoofingForking
missing:tag:RedirectionToNull
missing:tag:T1003.008
missing:tag:T1005
missing:tag:T1046
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1205
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.006
missing:tag:T1590
new
#57
opened Apr 19, 2022 by
timb-machine
[Intel]: https://scarybeastsecurity.blogspot.com/2011/07/alert-vsftpd-download-backdoored.html
missing:tactics
missing:tag:IRC
missing:tag:T1021.001
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1071.002
missing:tag:T1083
missing:tag:T1491
missing:tag:T1518
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:wltm
new
#49
opened Apr 19, 2022 by
timb-machine
[Intel]: https://www.trendmicro.com/en_us/research/21/l/the-evolution-of-iot-linux-malware-based-on-mitre-att&ck-ttps.html
missing:tactics
missing:tag:IRC
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1222
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1548.001
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#37
opened Apr 19, 2022 by
timb-machine
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.