Ezuri is an open-source Go-based runtime crypter and memory loader for Linux ELF binaries, created by Guilherme Thomazi Bonicontro (guitmz). It encrypts a payload using AES, decrypts it at runtime, and executes the resulting ELF directly from an anonymous memory-backed file through the Linux memfd_create mechanism rather than writing the payload to disk. This fileless execution and packing behavior is intended to reduce static antivirus visibility and has been observed to substantially lower detections for otherwise known malware samples. Ezuri has been abused by multiple Linux malware operators, including TeamTNT, which used it to package Tsunami and Black-T-related payloads in attacks against cloud and containerized Linux environments. Ezuri is a dual-use utility released publicly in 2019 and is commonly associated with Linux malware packing and defense-evasion tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AT&T reported that TeamTNT leveraged Ezuri, an open-source tool written in Go, to load a fileless payload in an earlier, separate cloud attack.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
According to a report released by AT&T Alien Labs, multiple threat actors are using Ezuri crypter to pack their malware and evade antivirus detection.
A Simple Linux ELF Runtime Crypter. An unpacker by f0wl can be found at f0wl/ezuri_unpack
The payload is encrypted with AES CFB and will be decrypted and run via memfd_create by the stub.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source ELF crypter used by TeamTNT to encrypt and execute payloads from memory, primarily to evade detection.
An open-source Go tool previously leveraged by TeamTNT to load a fileless payload; it is cited only as historical comparison to PyLoose.
An ELF loader/crypter referenced as a comparative example of tooling that can be used to drop fileless ELF malware via memfd_create and help malware evade detection.
A Golang-based ELF crypter and memory loader for Linux binaries that AES-encrypts malware payloads and executes the decrypted payload directly from memory without dropping files to disk, helping malware evade antivirus detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.