Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earth Lusca [is] using KTLVdoor, a new highly obfuscated multiplatform backdoor as part of a large-scale attack campaign.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Most of the samples discovered in this campaign are obfuscated: embedded strings are not directly readable, symbols are stripped and most of the functions and packages were renamed...
The backdoor’s configuration and communication involve sophisticated encryption and obfuscation techniques to hinder malware analysis.
It is highly obfuscated and is being spread in the wild impersonating various system utilities names or similar tools, such as sshd, java, sqlite, bash, edr-agent, and more.
The backdoor ... impersonates legitimate system utility names or tools such as sshd, java, sqlite, bash, edr-agent and more in both Windows and Linux OSes.
SoInject ... Run shellcode, Linux platform ReflectDllInject Run shellcode, Windows platform
Monitor networks within your environment for any suspicious reconnaissance tactics such as port scanning activities.
The backdoor’s configuration and communication involve sophisticated encryption and obfuscation techniques to hinder malware analysis.
The configuration file may contain ... proto string http, tcp, dns, icmp
The configuration file may contain ... proto string http, tcp, dns, icmp
73 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A highly obfuscated multiplatform Golang backdoor for Windows and Linux that masquerades as system utilities and enables full remote control, including command execution, file manipulation, system/network reconnaissance, proxying, upload/download, remote port scanning, and shellcode/DLL injection.
A Golang-based, highly obfuscated multiplatform backdoor for Windows and Linux. It masquerades as legitimate utilities such as sshd, java, sqlite, bash, and edr-agent; supports file manipulation, command execution, and remote port scanning; and uses encrypted and obfuscated configuration and C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.